ZeroHour

CVE-2018-0167

KEVmass

Buffer Overflow in Cisco IOS, IOS XE, and IOS XR LLDP Subsystem

CISA: Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

CVSS 3.1
8.8 high
EPSS
3%p88
Published
()
KEV added
AI analysis

Cisco IOS, IOS XE, and IOS XR software contain multiple buffer overflow flaws (CWE-119) in the Link Layer Discovery Protocol (LLDP) subsystem. An unauthenticated attacker positioned on an adjacent network segment can trigger the flaws by sending crafted LLDP packets that the affected device processes. Successful exploitation can crash the device (denial of service) or allow arbitrary code execution with elevated privileges. Any Cisco router, switch, or other device running affected IOS, IOS XE, or IOS XR software with LLDP enabled is exposed; LLDP is commonly enabled by default on Cisco interfaces, and Cisco Bug IDs are CSCuo17183 and CSCvd73487. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03, indicating known in-the-wild exploitation, with an EPSS 30-day exploitation probability of about 3.4% (88th percentile).

What to do: Apply updated IOS, IOS XE, or IOS XR software per Cisco's instructions, as required by CISA's KEV listing. As interim mitigation, disable LLDP or restrict it on interfaces facing untrusted or user-facing network segments, since exploitation requires adjacent (Layer 2) access. Audit which devices run affected software with LLDP enabled and prioritize remediation of transit, data center, and otherwise internet-reachable infrastructure.

Affected
cisco ios
cisco ios xe
cisco ios xr
Estimated exposure
massmillions of deployed Cisco IOS/IOS XE/IOS XR devices (practical exposure limited to devices with LLDP enabled and an adjacent attacker) — Cisco IOS/IOS XE/IOS XR is the operating system on a dominant share of enterprise and service-provider routing and switching installed bases, numbering in the millions of devices with hundreds of thousands visible in public internet scans,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCuo17183, CSCvd73487.

CISA Known Exploited Vulnerability
Affected
Cisco IOS, XR, and XE Software
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
ios, ios xe, ios xr
Weakness
CWE-119
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.