ZeroHour

CVE-2018-0175

KEVmass

Format String Flaw in Cisco IOS, IOS XE, and IOS XR LLDP Subsystem Enables RCE

CISA: Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

CVSS 3.1
8.0 high
EPSS
3%p88
Published
()
KEV added
AI analysis

CVE-2018-0175 is a format string vulnerability (CWE-134/CWE-119) in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE, and IOS XR software (CVSS 3.1: 8.0 High). An unauthenticated attacker positioned on an adjacent network segment can trigger it by sending crafted LLDP packets to an affected device. Successful exploitation can crash the device (denial of service) or allow execution of arbitrary code with elevated privileges on the router or switch. Any organization running affected Cisco IOS, IOS XE, or IOS XR releases is exposed, with the greatest risk on devices that process LLDP on interfaces reachable from untrusted neighboring devices. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03, required action: apply updates per vendor instructions), so exploitation is confirmed in the wild; EPSS currently estimates a 3.5% chance of exploitation within 30 days (88th percentile), and no public proof-of-concept is known.

What to do: Inventory all IOS, IOS XE, and IOS XR devices, check whether LLDP is enabled (e.g., via 'show lldp'), and upgrade to the fixed releases listed in the Cisco advisory for Bug ID CSCvd73664, per CISA's KEV required action. As an interim mitigation, disable LLDP on interfaces facing untrusted networks where it is not operationally required. Prioritize patching devices in shared or tenant-adjacent environments (campus access, provider edge, internet demarcation) given the adjacent-vector, unauthenticated nature of the flaw.

Affected
Cisco IOS
Cisco IOS XE
Cisco IOS XR
Estimated exposure
mass≈ millions of deployed devices worldwide (public internet scans show hundreds of thousands of Cisco IOS/IOS XE devices exposing management services) — Cisco IOS, IOS XE, and IOS XR are among the most widely deployed network operating systems in enterprise campus, branch, and service-provider networks, and public scan datasets report on the order of hundreds of thousands of Cisco devices…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCvd73664.

CISA Known Exploited Vulnerability
Affected
Cisco IOS, XR, and XE Software
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
ios, ios xe, ios xr
Weakness
CWE-119, CWE-134
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.