CVE-2018-0175
Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
Description
CVE-2018-0175 is a remote code execution vulnerability in Cisco IOS, XR, and XE Software. Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Successful exploitation could allow an attacker to execute arbitrary code or cause a denial-of-service condition on affected devices. CISA has added CVE-2018-0175 to the Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The EPSS score of 2.17% (84.1th percentile) indicates a measurable likelihood of exploitation activity.
KEV Information
CVSS Score
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HOpen in CalculatorCWEs
Affected Products
| Vendor | Product | Version |
|---|---|---|
| cisco | ios | 15.4\(3\)m4.1; <= 15.2\(4a\)ea5; <= 15.2\(6\)e0a; <= 15.6.3m1 |
| cisco | ios xe | 15.4\(3\)m4.1; <= 15.2\(4a\)ea5; <= 15.2\(6\)e0a; <= 15.6.3m1 |
| cisco | ios xr | 15.4\(3\)m4.1 |
Multiple CVSS Assessments
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References
- http://www.securityfocus.com/bid/103564(Broken Link, Third Party Advisory, VDB Entry)
- http://www.securitytracker.com/id/1040586(Broken Link, Third Party Advisory, VDB Entry)
- https://ics-cert.us-cert.gov/advisories/ICSA-18-107-03(Third Party Advisory, US Government Resource)
- https://ics-cert.us-cert.gov/advisories/ICSA-18-107-04(Third Party Advisory, US Government Resource)
- https://ics-cert.us-cert.gov/advisories/ICSA-18-107-05(Third Party Advisory, US Government Resource)
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-lldp(Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-0175(US Government Resource)
Weakness Type
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
Improper Restriction of Operations within the Bounds of a Memory Buffer occurs when software performs operations on a memory buffer but can read from or write to a memory location that is outside the intended boundary of the buffer. This is the parent category for many specific buffer error types including buffer overflows (CWE-120), buffer underflows, out-of-bounds reads (CWE-125), and out-of-bounds writes (CWE-787).
Learn more: CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer
Impact Analysis
CVE-2018-0175 poses a severe threat to organizations running Cisco IOS, XR, and XE Software, as it enables unauthenticated attackers to execute arbitrary code on affected devices. With a CVSS score of 8 (HIGH), the vulnerability allows attackers operating from an adjacent network segment to compromise the affected device. A successful attack could lead to full device takeover, allowing adversaries to intercept network traffic, modify routing configurations, and use compromised devices as pivot points for lateral movement within the network. Given the critical role of network infrastructure devices in enterprise environments, compromise could disrupt business operations, enable data exfiltration, and undermine the security posture of the entire network.
Exploit Maturity
CVE-2018-0175 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming that this vulnerability has been exploited in real-world attacks. The EPSS score of 2.17% (84.1th percentile) indicates a measurable probability of exploitation. Organizations should treat this vulnerability as an active and ongoing threat requiring immediate remediation.
Remediation
- Apply vendor updates immediately as required by CISA KEV: Apply updates per vendor instructions.
- If immediate patching is not possible, implement interim mitigations such as restricting access to the affected LLDP protocol service to trusted networks only using access control lists.
- Monitor affected devices for signs of exploitation, including unexpected reloads, unusual network traffic, and anomalous process behavior.
- Audit compromised devices for unauthorized configuration changes, unexpected user accounts, and persistent backdoors.
- Consider implementing network segmentation to limit the blast radius of a compromised network device.
Technical Details
CVE-2018-0175 is a remote code execution vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, XR, and XE Software. The vulnerability allows an unauthenticated adjacent attacker to send specially crafted packets from the same network segment to trigger a buffer overflow condition, potentially leading to arbitrary code execution with elevated privileges. The CVSS v3.1 score of 8 reflects low attack complexity with user interaction required, and high impact across confidentiality, integrity, and availability. The attack is conducted via adjacent network.
Frequently Asked Questions
Is CVE-2018-0175 being actively exploited?
Yes. CVE-2018-0175 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation. The EPSS score of 2.17% (84.1th percentile) further indicates a notable likelihood of ongoing exploitation.
What products are affected by CVE-2018-0175?
CVE-2018-0175 affects Cisco IOS, XR, and XE Software. Specifically, affected products include Cisco Ios, Cisco Ios Xe, Cisco Ios Xr.
How do I fix CVE-2018-0175?
Apply updates per vendor instructions. As this vulnerability allows remote code execution, prioritize patching immediately. If patching is delayed, restrict access to the vulnerable LLDP protocol service and monitor for exploitation attempts.
How severe is CVE-2018-0175?
CVE-2018-0175 has a CVSS score of 8 (HIGH). This is a high-severity vulnerability that enables remote code execution, which could lead to complete compromise of network infrastructure devices. The combination of no authentication requirement and low attack complexity makes this a significant threat.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.