SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2018-0180

Cisco IOS Software Denial-of-Service Vulnerability

KEVMEDIUM 5.9EPSS 4.93%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 17 March 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Cisco Bug IDs: CSCuy32360, CSCuz60599.

CVSS 3.1
5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
4.93% probability · 92th percentile
CISA KEV
Listed 3 March 2022 · due 17 March 2022
Weakness
CWE-399
Affected
cisco/ios
Source
psirt@cisco.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2018-0180

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.