CVE-2018-0179
KEVmassUnauthenticated Remote Denial-of-Service in Cisco IOS Login Block
CISA: Cisco IOS Software Denial-of-Service Vulnerability
CVE-2018-0179 is a denial-of-service vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software, tracked under Cisco Bug IDs CSCuy32360 and CSCuz60599. An unauthenticated, remote attacker can send traffic that triggers a reload of the affected device, although the high attack complexity (CVSS AC:H) means exploitation requires fairly specific conditions. Successful exploitation yields loss of availability only: the device reloads and interrupts network service, with no confidentiality or integrity impact. Any Cisco device running IOS Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later is affected. The flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), confirming in-the-wild exploitation, though no public proof-of-concept is known and ransomware use has not been established.
What to do: Apply Cisco's fixed releases per the vendor advisory (Bug IDs CSCuy32360, CSCuz60599), as required by CISA's KEV catalog; use 'show version' to identify devices on affected 15.4(2)T, 15.4(3)M, or 15.4(2)CG trains or later, and check whether the Login Block feature ('login block-for') is configured. As interim mitigation, restrict unauthenticated access to device login and management interfaces (e.g., ACLs on VTY lines) until patched.
| Cisco IOS | 15.4(2)T, 15.4(3)M, and 15.4(2)CG and later |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Cisco Bug IDs: CSCuy32360, CSCuz60599.
- Affected
- Cisco IOS Software
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- ios
- Weakness
- CWE-399
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.