ZeroHour

CVE-2018-0179

KEVmass

Unauthenticated Remote Denial-of-Service in Cisco IOS Login Block

CISA: Cisco IOS Software Denial-of-Service Vulnerability

CVSS 3.1
5.9 medium
EPSS
5%p92
Published
()
KEV added
AI analysis

CVE-2018-0179 is a denial-of-service vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software, tracked under Cisco Bug IDs CSCuy32360 and CSCuz60599. An unauthenticated, remote attacker can send traffic that triggers a reload of the affected device, although the high attack complexity (CVSS AC:H) means exploitation requires fairly specific conditions. Successful exploitation yields loss of availability only: the device reloads and interrupts network service, with no confidentiality or integrity impact. Any Cisco device running IOS Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later is affected. The flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), confirming in-the-wild exploitation, though no public proof-of-concept is known and ransomware use has not been established.

What to do: Apply Cisco's fixed releases per the vendor advisory (Bug IDs CSCuy32360, CSCuz60599), as required by CISA's KEV catalog; use 'show version' to identify devices on affected 15.4(2)T, 15.4(3)M, or 15.4(2)CG trains or later, and check whether the Login Block feature ('login block-for') is configured. As interim mitigation, restrict unauthenticated access to device login and management interfaces (e.g., ACLs on VTY lines) until patched.

Affected
Cisco IOS15.4(2)T, 15.4(3)M, and 15.4(2)CG and later
Estimated exposure
masshundreds of thousands of internet-exposed Cisco IOS devices — Public internet scan data (Shodan/Censys-type counts) consistently ranks Cisco IOS among the most exposed network operating systems with on the order of 10^5 remotely reachable devices, and the broad 'and later' 15.x version range means…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Cisco Bug IDs: CSCuy32360, CSCuz60599.

CISA Known Exploited Vulnerability
Affected
Cisco IOS Software
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
ios
Weakness
CWE-399
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.