CVE-2018-0173
KEVmassUnauthenticated DoS in Cisco IOS/IOS XE via crafted DHCPv4 option 82
CISA: Cisco IOS and IOS XE Software Improper Input Validation Vulnerability
CVE-2018-0173 is an improper input validation flaw (CWE-20) in the Cisco IOS and IOS XE code path that restores encapsulated DHCP option 82 (Relay Agent Information) data in DHCPv4 packets. An unauthenticated, remote attacker can trigger it by sending a crafted DHCPv4 packet to a device acting as a DHCP relay; when the device forwards it to a DHCPv4 server and then processes the option 82 information encapsulated in the server's DHCPOFFER response, a processing error occurs. A successful exploit causes the affected device to reload, producing a Relay Reply denial-of-service condition — no confidentiality or integrity impact, but complete loss of availability on that device (CVSS 3.1 8.6, scope-changed, availability-high). Any Cisco IOS or IOS XE device with the DHCPv4 relay/option 82 feature in the data path is affected; the source data does not specify affected release ranges, so administrators must consult Cisco's advisory (Bug ID CSCvg62754, CNA: [email protected]) for their train. Exploitation is confirmed: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03 (ransomware use unknown, required action: apply vendor updates), EPSS estimates a 7.6% probability of exploitation in the next 30 days (94th percentile), and no public proof-of-concept is known.
What to do: Inventory IOS/IOS XE devices configured for DHCPv4 relay (check for 'ip helper-address' / 'ip dhcp relay information option' in the running config and confirm the release with 'show version'), then upgrade to the fixed releases listed in Cisco's advisory for Bug ID CSCvg62754. If patching must wait, use interface ACLs to prevent untrusted hosts from sending DHCP packets to relay interfaces, since exploitation requires no credentials or user interaction. The CISA KEV entry (added 2022-03-03) mandates applying the vendor updates, so prioritize internet-facing and site-gateway relay devices.
| Cisco IOS | — |
| Cisco IOS XE | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a Relay Reply denial of service (DoS) condition. The vulnerability exists because the affected software performs incomplete input validation of encapsulated option 82 information that it receives in DHCPOFFER messages from DHCPv4 servers. An attacker could exploit this vulnerability by sending a crafted DHCPv4 packet to an affected device, which the device would then forward to a DHCPv4 server. When the affected software processes the option 82 information that is encapsulated in the response from the server, an error could occur. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvg62754.
- Affected
- Cisco IOS and IOS XE Software
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- ios, ios xe
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H