CVE-2018-0161
KEVlargeAuthenticated SNMP DoS in Cisco IOS on Catalyst 2960-L and Digital Building switches
CISA: Cisco IOS Software Resource Management Errors Vulnerability
CVE-2018-0161 is a resource-management flaw (CWE-399) in the Simple Network Management Protocol subsystem of Cisco IOS on certain Catalyst switch models. An authenticated, remote attacker triggers it by sending an SNMPv2c or SNMPv3 GET request for the ciscoFlashMib object ID (OID) to an affected device; processing this request can produce a SYS-3-CPUHOG condition and force the switch to restart. The impact is denial of service on the switch only, with no confidentiality or integrity loss. Only Cisco Catalyst 2960-L Series, Catalyst Digital Building Series 8P, and Catalyst Digital Building Series 8U switches running a vulnerable IOS release with SNMPv2c or SNMPv3 configured are affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03, confirming in-the-wild exploitation; ransomware use is unknown, EPSS is moderate at ~4.1% (90th percentile), and no public PoC is known.
What to do: Upgrade Cisco IOS on the affected Catalyst 2960-L and Digital Building switches to a fixed release per Cisco's advisory for bug CSCvd89541; this is a required action under the CISA KEV catalog. As interim mitigation, restrict SNMP (UDP 161) to trusted management hosts with ACLs or disable SNMPv2c/v3 where unused, and rotate/default-check community strings since exploitation requires valid SNMP credentials. Hunt for compromise indicators by checking switch logs for SYS-3-CPUHOG-forced reloads that coincide with SNMP GET requests for the ciscoFlashMIB OID.
| Cisco IOS Software on Catalyst 2960-L Series Switches | — |
| Cisco IOS Software on Catalyst Digital Building Series Switches 8P | — |
| Cisco IOS Software on Catalyst Digital Building Series Switches 8U | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial of service (DoS) condition, aka a GET MIB Object ID Denial of Service Vulnerability. The vulnerability is due to a condition that could occur when the affected software processes an SNMP read request that contains a request for the ciscoFlashMIB object ID (OID). An attacker could trigger this vulnerability by issuing an SNMP GET request for the ciscoFlashMIB OID on an affected device. A successful exploit could cause the affected device to restart due to a SYS-3-CPUHOG. This vulnerability affects the following Cisco devices if they are running a vulnerable release of Cisco IOS Software and are configured to use SNMP Version 2 (SNMPv2) or SNMP Version 3 (SNMPv3): Cisco Catalyst 2960-L Series Switches, Cisco Catalyst Digital Building Series Switches 8P, Cisco Catalyst Digital Building Series Switches 8U. Cisco Bug IDs: CSCvd89541.
- Affected
- Cisco IOS Software
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- ios
- Weakness
- CWE-399
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.