ZeroHour

CVE-2018-0159

KEVmass

Unauthenticated IKEv1 Packet DoS (Device Reload) in Cisco IOS and IOS XE

CISA: Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability

CVSS 3.1
7.5 high
EPSS
7%p94
Published
()
KEV added
AI analysis

CVE-2018-0159 is an improper input validation flaw (CWE-20) in the Internet Key Exchange Version 1 (IKEv1) implementation of Cisco IOS and Cisco IOS XE software. An unauthenticated, remote attacker can trigger it by sending crafted IKEv1 packets to an affected device during an IKE negotiation, typically against a device listening for IKE on UDP 500/4500 such as an IPsec VPN gateway. A successful attack forces the device to reload, causing a denial of service; there is no confidentiality or integrity impact, consistent with the CVSS 3.1 score of 7.5 (AV:N/AC:L/PR:N/UI:N/A:H). Any organization running Cisco IOS or IOS XE on routers, switches, or VPN endpoints with IKEv1 enabled is potentially affected, with exposure concentrated on internet-reachable VPN concentrators. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03, and EPSS estimates a 6.9% chance of exploitation within 30 days (94th percentile), though no public proof-of-concept is known.

What to do: Apply fixed Cisco IOS/IOS XE software per Cisco's advisory and the CISA KEV required action, prioritizing internet-facing VPN gateways and concentrators. Inventory devices for IKEv1 use (crypto ISAKMP configuration, IKE listeners on UDP 500/4500) and, where patching is delayed, restrict IKE traffic to trusted peer addresses using infrastructure ACLs or disable IKEv1 if only IKEv2 is required.

Affected
Cisco IOS Software
Cisco IOS XE Software
Estimated exposure
mass≈hundreds of thousands of internet-reachable devices (Cisco IOS/IOS XE installed base in the millions) — Cisco IOS and IOS XE are the dominant operating systems on enterprise routers and switches with a multi-million-device installed base, and public internet scans routinely surface hundreds of thousands of exposed Cisco network devices, a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of specific IKEv1 packets. An attacker could exploit this vulnerability by sending crafted IKEv1 packets to an affected device during an IKE negotiation. A successful exploit could allow the attacker to cause an affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCuj73916.

CISA Known Exploited Vulnerability
Affected
Cisco IOS Software and Cisco IOS XE Software
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
ios, ios xe
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.