CVE-2018-0175
KEVmassFormat String Flaw in Cisco IOS, IOS XE, and IOS XR LLDP Subsystem Enables RCE
CISA: Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
CVE-2018-0175 is a format string vulnerability (CWE-134/CWE-119) in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE, and IOS XR software (CVSS 3.1: 8.0 High). An unauthenticated attacker positioned on an adjacent network segment can trigger it by sending crafted LLDP packets to an affected device. Successful exploitation can crash the device (denial of service) or allow execution of arbitrary code with elevated privileges on the router or switch. Any organization running affected Cisco IOS, IOS XE, or IOS XR releases is exposed, with the greatest risk on devices that process LLDP on interfaces reachable from untrusted neighboring devices. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03, required action: apply updates per vendor instructions), so exploitation is confirmed in the wild; EPSS currently estimates a 3.5% chance of exploitation within 30 days (88th percentile), and no public proof-of-concept is known.
What to do: Inventory all IOS, IOS XE, and IOS XR devices, check whether LLDP is enabled (e.g., via 'show lldp'), and upgrade to the fixed releases listed in the Cisco advisory for Bug ID CSCvd73664, per CISA's KEV required action. As an interim mitigation, disable LLDP on interfaces facing untrusted networks where it is not operationally required. Prioritize patching devices in shared or tenant-adjacent environments (campus access, provider edge, internet demarcation) given the adjacent-vector, unauthenticated nature of the flaw.
| Cisco IOS | — |
| Cisco IOS XE | — |
| Cisco IOS XR | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCvd73664.
- Affected
- Cisco IOS, XR, and XE Software
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- ios, ios xe, ios xr
- Weakness
- CWE-119, CWE-134
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.