cbcvebase.
CVE-2018-0155
published 2018-03-28

CVE-2018-0155: A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series…

PriorityP279high8.6CVSS 3.1
AVNACLPRNUINSCCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-17
Exploited in the wild
EPSS
7.89%
94.1th percentile
A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial of service (DoS) condition. The vulnerability is due to insufficient error handling when the BFD header in a BFD packet is incomplete. An attacker could exploit this vulnerability by sending a crafted BFD message to or across an affected switch. A successful exploit could allow the attacker to trigger a reload of the system. This vulnerability affects Catalyst 4500 Supervisor Engine 6-E (K5), Catalyst 4500 Supervisor Engine 6L-E (K10), Catalyst 4500 Supervisor Engine 7-E (K10), Catalyst 4500 Supervisor Engine 7L-E (K10), Catalyst 4500E Supervisor Engine 8-E (K10), Catalyst 4500E Supervisor Engine 8L-E (K10), Catalyst 4500E Supervisor Engine 9-E (K10), Catalyst 4500-X Series Switches (K10), Catalyst 4900M Switch (K5), Catalyst 4948E Ethernet Switch (K5). Cisco Bug IDs: CSCvc40729.

Affected

3 ranges
VendorProductVersion rangeFixed in
ciscoios
ciscoios_and_ios_xe
ciscoios_xe

Detection & IOCsextracted from sources · hover to see the quote

processiosd
  • Detect crafted BFD packets with an incomplete BFD header sent to or across Cisco Catalyst 4500/4500-X Series Switches; such packets can trigger a crash of the iosd process and a device reload.
  • Monitor for unexpected iosd process crashes or unplanned system reloads on Cisco Catalyst 4500/4500-X Series Switches as an indicator of exploitation.
  • ·Vulnerability is specific to the BFD offload implementation; only Catalyst 4500/4500-X Series Switches with BFD offload enabled are affected. Affected supervisor engines include: 6-E (K5), 6L-E (K10), 7-E (K10), 7L-E (K10), 8-E (K10), 8L-E (K10), 9-E (K10), 4500-X (K10), 4900M (K5), and 4948E (K5).
  • ·There are no workarounds available for this vulnerability; patching via vendor software updates is the only remediation.

CVSS provenance

nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vulncheck8.6HIGH
cisa8.6HIGH
vendor_cisco8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.