HIGH CISA KEV

CVE-2018-0156

CVSS v3

7.5

HIGH

EPSS Score

12.1%

exploit probability

CISA KEV

Yes

known exploited

Exploitation

SSVC status

Description

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted packet to an affected device on TCP port 4786. Only Smart Install client switches are affected. Cisco devices that are configured as a Smart Install director are not affected by this vulnerability. Cisco Bug IDs: CSCvd40673.

CISA Known Exploited Vulnerability

Date Added
3/3/2022
Patch Due Date
3/17/2022
Ransomware Use
Unknown

Technical details

Published
3/28/2018

Frequently asked questions

What is CVE-2018-0156?

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted packet to an affected device on TCP port 4786. Only Smart Install client switches are affected. Cisco devices that are configured as a Smart Install director are not affected by this vulnerability. Cisco Bug IDs: CSCvd40673.

Is CVE-2018-0156 actively exploited?

Yes. CVE-2018-0156 is on the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning it has been confirmed as actively exploited in the wild. CISA requires federal agencies to patch by 3/17/2022.

What is the CVSS score for CVE-2018-0156?

CVE-2018-0156 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2018-0156 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.