ZeroHour

CVE-2018-0180

KEVmass

Unauthenticated Remote DoS in Cisco IOS Login Block Feature

CISA: Cisco IOS Software Denial-of-Service Vulnerability

CVSS 3.1
5.9 medium
EPSS
5%p92
Published
()
KEV added
AI analysis

Multiple flaws in the Login Enhancements (Login Block) feature of Cisco IOS Software allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service. The flaw is triggered through crafted login attempts against devices where the Login Block feature is enabled; no authentication or user interaction is required and no information is disclosed. An attacker gains the ability to repeatedly reload the device, disrupting connectivity on the affected box. Any Cisco device running IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later is affected, which in practice means branch and WAN edge routers and similar IOS devices with the Login Block configuration applied. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03, indicating known in-the-wild exploitation, and EPSS assigns a 4.9% (92nd percentile) probability of exploitation in the next 30 days; no public proof-of-concept is known.

What to do: Upgrade affected devices to fixed Cisco IOS releases per Cisco's advisory (referencing bug IDs CSCuy32360 and CSCuz60599), as required by CISA's KEV listed action. As an interim mitigation, consider removing the Login Block configuration from VTY lines and restricting remote login access to trusted management hosts with ACLs. Inventory devices running IOS 15.4(2)T, 15.4(3)M, or 15.4(2)CG or later and prioritize those exposed to untrusted networks.

Affected
Cisco IOS15.4(2)T, 15.4(3)M, and 15.4(2)CG and later (Cisco Bug IDs CSCuy32360, CSCuz60599)
Estimated exposure
mass≈hundreds of thousands of Cisco IOS devices in the 15.4(3)M/15.4(2)T/15.4(2)CG installed base, with the exploitable subset limited to those with Login Block… — Cisco IOS 15.4(3)M and 15.4(2)T were long-lived, widely deployed enterprise routing releases, so the affected installed base plausibly exceeds 100,000 devices, though only systems running the Login Enhancements (Login Block) feature can be…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Cisco Bug IDs: CSCuy32360, CSCuz60599.

CISA Known Exploited Vulnerability
Affected
Cisco IOS Software
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
ios
Weakness
CWE-399
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.