CVE-2018-0161

MEDIUM(6.3)KEV

Cisco IOS Software Resource Management Errors Vulnerability

Description

CVE-2018-0161 is a denial-of-service vulnerability in Cisco IOS Software. A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial-of-service (DoS) condition. Successful exploitation could result in denial of service through system crashes on affected devices. CISA has added CVE-2018-0161 to the Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The EPSS score of 0.67% (71.1st percentile) indicates a measurable likelihood of exploitation activity.

KEV Information

Vendor
Cisco
Product
IOS Software
Date Added
March 3, 2022
Due Date
March 17, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
4.0

CWEs

Affected Products

VendorProductVersion
ciscoios15.2\(5\)e

Multiple CVSS Assessments

Source: [email protected](Primary)
6.3
MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
6.3
MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H

References

Weakness Type

CWE-399: Resource Management Errors

CWE-399 (Resource Management Errors) is a weakness classification that describes the underlying vulnerability mechanism exploited in CVE-2018-0161. In this case, the weakness relates to how Cisco IOS Software handles SNMP protocol processing, leading to exploitable conditions.

Learn more: CWE-399 — Resource Management Errors

Impact Analysis

CVE-2018-0161 threatens the availability of Cisco IOS Software, as exploitation can cause denial-of-service conditions, resulting in service disruption. With a CVSS score of 6.3 (MEDIUM) and a network-based attack vector, the barrier to exploitation is moderate. The changed scope indicates that exploitation can affect resources beyond the vulnerable component, potentially impacting downstream network services and connected systems. In enterprise environments, repeated exploitation could cause sustained network outages affecting business operations, communications, and service availability. Network infrastructure devices are high-value targets, and their unavailability can have cascading effects across the organization.

Exploit Maturity

CVE-2018-0161 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming that this vulnerability has been exploited in real-world attacks. The EPSS score of 0.67% (71.1st percentile) indicates a measurable probability of exploitation. Organizations should treat this vulnerability as an active and ongoing threat requiring immediate remediation.

Remediation

  1. Apply vendor updates immediately as required by CISA KEV: Apply updates per vendor instructions.
  2. If immediate patching is not possible, implement interim mitigations such as restricting access to the affected SNMP service to trusted networks only using access control lists.
  3. Monitor affected devices for signs of exploitation, including unexpected reloads, unusual SNMP traffic, and anomalous process behavior.
  4. Ensure network monitoring and alerting is configured to detect denial-of-service conditions affecting the Cisco IOS Software infrastructure.
  5. Maintain up-to-date device configurations and backups to enable rapid recovery if exploitation causes device reloads.

Technical Details

CVE-2018-0161 is a denial-of-service vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software. The vulnerability allows an authenticated remote attacker to cause a denial-of-service condition by sending specially crafted SNMP packets. The CVSS v3.1 score of 6.3 reflects high attack complexity, the need for authentication, and high impact on availability. The changed scope in the CVSS vector indicates that exploitation can impact resources beyond the vulnerable component itself.

Frequently Asked Questions

Is CVE-2018-0161 being actively exploited?

Yes. CVE-2018-0161 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation. The EPSS score of 0.67% (71.1st percentile) further indicates a notable likelihood of ongoing exploitation.

What products are affected by CVE-2018-0161?

CVE-2018-0161 affects Cisco IOS Software. Specifically, affected products include Cisco Ios.

How do I fix CVE-2018-0161?

Apply updates per vendor instructions. If immediate patching is not feasible, apply interim mitigations such as access control restrictions and enhanced monitoring to detect exploitation attempts.

How severe is CVE-2018-0161?

CVE-2018-0161 has a CVSS score of 6.3 (MEDIUM). This is a medium-severity denial-of-service vulnerability that can disrupt network operations. While it does not enable code execution, the availability impact on critical network infrastructure makes timely remediation essential.

CVSS Score

6.3
MEDIUM(6.3)

EPSS Score

EPSS Score4.67%
EPSS Percentile91.0%

Dates

PublishedMarch 28, 2018
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.