CVE-2018-0167
KEVmassBuffer Overflow in Cisco IOS, IOS XE, and IOS XR LLDP Subsystem
CISA: Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
Cisco IOS, IOS XE, and IOS XR software contain multiple buffer overflow flaws (CWE-119) in the Link Layer Discovery Protocol (LLDP) subsystem. An unauthenticated attacker positioned on an adjacent network segment can trigger the flaws by sending crafted LLDP packets that the affected device processes. Successful exploitation can crash the device (denial of service) or allow arbitrary code execution with elevated privileges. Any Cisco router, switch, or other device running affected IOS, IOS XE, or IOS XR software with LLDP enabled is exposed; LLDP is commonly enabled by default on Cisco interfaces, and Cisco Bug IDs are CSCuo17183 and CSCvd73487. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03, indicating known in-the-wild exploitation, with an EPSS 30-day exploitation probability of about 3.4% (88th percentile).
What to do: Apply updated IOS, IOS XE, or IOS XR software per Cisco's instructions, as required by CISA's KEV listing. As interim mitigation, disable LLDP or restrict it on interfaces facing untrusted or user-facing network segments, since exploitation requires adjacent (Layer 2) access. Audit which devices run affected software with LLDP enabled and prioritize remediation of transit, data center, and otherwise internet-reachable infrastructure.
| cisco ios | — |
| cisco ios xe | — |
| cisco ios xr | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCuo17183, CSCvd73487.
- Affected
- Cisco IOS, XR, and XE Software
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- ios, ios xe, ios xr
- Weakness
- CWE-119
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.