SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2018-0167

Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

KEVHIGH 8.8EPSS 3.35%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 17 March 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCuo17183, CSCvd73487.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
3.35% probability · 88th percentile
CISA KEV
Listed 3 March 2022 · due 17 March 2022
Weakness
CWE-119
Affected
cisco/ios · cisco/ios xe · cisco/ios xr
Source
psirt@cisco.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2018-0167

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.