ZeroHour

CVE-2018-0172

KEVmass

Unauthenticated DoS via DHCP option 82 heap overflow in Cisco IOS and IOS XE

CISA: Cisco IOS and IOS XE Software Improper Input Validation Vulnerability

CVSS 3.1
8.6 high
EPSS
8%p94
Published
()
KEV added
AI analysis

Cisco IOS and IOS XE Software improperly validate DHCP option 82 information received in DHCPv4 packets from DHCP relay agents, creating a heap overflow condition. An unauthenticated, remote attacker can trigger the flaw by sending a crafted DHCPv4 packet with option 82 data to an affected device. Successful exploitation causes the device to reload, resulting in a denial of service; no confidentiality or integrity impact is expected, but availability of the networking device is lost. Any Cisco IOS or IOS XE device that processes option 82 information in DHCPv4 packets is affected. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added March 3, 2022), indicating confirmed exploitation in the wild, and EPSS assigns it a ~7.8% probability of exploitation over the next 30 days.

What to do: Upgrade affected Cisco IOS and IOS XE devices to a fixed release listed in the Cisco security advisory for Bug ID CSCvg62730, per the vendor's instructions. Until patched, restrict DHCPv4 traffic to trusted DHCP relay agents and avoid exposing DHCP relay functionality to untrusted networks, and check whether DHCP relay/option 82 is enabled on exposed devices. Monitor devices for unexpected reloads as a sign of attempted exploitation.

Affected
Cisco IOSMultiple affected releases of Cisco IOS Software; fixed releases are specified per platform in the Cisco security advisory (Bug ID CSCvg62730)
Cisco IOS XEMultiple affected releases of Cisco IOS XE Software; fixed releases are specified per platform in the Cisco security advisory (Bug ID CSCvg62730)
Estimated exposure
massorder of 1 million+ deployed devices, with hundreds of thousands of IOS/IOS XE devices visible in public internet scans (exploitability limited to devices… — Cisco IOS/IOS XE is among the most widely deployed network operating systems on enterprise and service-provider routers and switches, and public internet scans consistently surface hundreds of thousands of such devices, though only those…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software performs incomplete input validation of option 82 information that it receives in DHCP Version 4 (DHCPv4) packets from DHCP relay agents. An attacker could exploit this vulnerability by sending a crafted DHCPv4 packet to an affected device. A successful exploit could allow the attacker to cause a heap overflow condition on the affected device, which will cause the device to reload and result in a DoS condition. Cisco Bug IDs: CSCvg62730.

CISA Known Exploited Vulnerability
Affected
Cisco IOS and IOS XE Software
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
ios, ios xe
Weakness
CWE-20, CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

In the news