CVE-2018-0156 - Cisco IOS Software and Cisco IOS XE Software
AI Vulnerability ContextA vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted packet to an affected device on TCP port 4786. Only S...
Overview
A source-backed snapshot of this vulnerability.
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted packet to an affected device on TCP port 4786. Only Smart Install client switches are affected. Cisco devices that are configured as a Smart Install director are not affected by this vulnerability. Cisco Bug IDs: CSCvd40673.
Vulnerability status
How serious this vulnerability is and whether it is known to be exploited.
- CVE ID
- CVE-2018-0156
- Vendor/project
- Cisco
- Product
- IOS Software and Cisco IOS XE Software
- Vulnerability name
- Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability
- Date added
- 2022-03-03
- Due date
- 2022-03-17
- Known ransomware campaign use
- Unknown
- CVSS v3
- 7.5
Exploit context
What the vulnerability is about.
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted packet to an affected device on TCP port 4786. Only Smart Install client switches are affected. Cisco devices that are configured as a Smart Install director are not affected by this vulnerability. Cisco Bug IDs: CSCvd40673.
Source evidence
Original public records and references for this page.
Original source
Original source links
Open the public records and source datasets used for this page.
