CVE-2018-0156
published 2018-03-28CVE-2018-0156: A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a…
PriorityP180high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-17
Exploited in the wild
EPSS
8.30%
94.3th percentile
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted packet to an affected device on TCP port 4786. Only Smart Install client switches are affected. Cisco devices that are configured as a Smart Install director are not affected by this vulnerability. Cisco Bug IDs: CSCvd40673.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios_and_ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor and alert on inbound TCP connections to port 4786 (Cisco Smart Install) from untrusted/external sources, as exploitation involves sending a crafted packet to this port. ↗
- →Only Smart Install client switches are affected; Smart Install director-configured devices are not. Focus detection on client-role Cisco IOS/IOS XE switches exposed on TCP/4786. ↗
- →Smart Install client functionality is enabled by default on unpatched switches; inventory and identify all switches running Cisco IOS Software releases that have not been updated to address Cisco bug ID CSCvd36820 as high-priority detection targets. ↗
- ·No workarounds are available for this vulnerability; patching is the only remediation. Disabling or blocking Smart Install (TCP/4786) where not needed can reduce attack surface. ↗
- ·Smart Install client is enabled by default on affected unpatched Cisco IOS switches, meaning devices may be unknowingly exposed without explicit configuration. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vulncheck7.5HIGH
cisa7.5HIGH
vendor_cisco8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability
cisa·2022-03-03·CVSS 7.5
CVE-2018-0156 [HIGH] CWE-399 Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability
Vulnerability: Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability
Affected: Cisco IOS Software and Cisco IOS XE Software
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial-of-service (DoS) condition.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-0156
Remediation Due Date: 2022-03-17
CISA ICS
Rockwell Automation Stratix Industrial Managed Ethernet Switch
cisa_ics·2018-04-25·CVSS 9.8
[CRITICAL] Rockwell Automation Stratix Industrial Managed Ethernet Switch
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix Industrial Managed Ethernet Switch
Last RevisedApril 25, 2018
Alert CodeICSA-18-107-05
## 1. EXECUTIVE SUMMARY
-
CVSS v3 9.8
- ATTENTION: Exploitable remotely/low skill level to exploit.
- Vendor: Rockwell Automation
- Equipment: Allen-Bradley Stratix Industrial Managed Ethernet Switch
- Vulnerabilities: Improper Input Validation, Resource Management Errors, 7PK – Errors, Improper Restriction of Operations within the Bounds of a Memory Buffer, Use of Externally-Controlled Format String.
## 2. RISK EVALUATION
Successful exploitation of these vuln
CISA ICS
Rockwell Automation Stratix and ArmorStratix Switches
cisa_ics·2018-04-25
Rockwell Automation Stratix and ArmorStratix Switches
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix and ArmorStratix Switches
Last RevisedApril 25, 2018
Alert CodeICSA-18-107-04
## 1. EXECUTIVE SUMMARY
-
CVSS v3 9.8
- ATTENTION: Exploitable remotely/low skill level to exploit.
- Vendor: Rockwell Automation
- Equipment: Allen-Bradley Stratix and ArmorStratix Switches
- Vulnerabilities: Improper Input Validation, Resource Management Errors, Improper Restriction of Operations within the Bounds of a Memory Buffer, Use of Externally-Controlled Format String.
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could result in loss
Cisco
Cisco IOS and IOS XE Software Smart Install Denial of Service Vulnerability
vendor_cisco·2018-03-28·CVSS 8.6
CVE-2018-0156 [HIGH] CWE-399 Cisco IOS and IOS XE Software Smart Install Denial of Service Vulnerability
Cisco IOS and IOS XE Software Smart Install Denial of Service Vulnerability
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition.
The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted packet to an affected device on TCP port 4786.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Smart Install client functionality is enabled by default on switches that are running Cisco IOS Software releases that have not been updated to address Cisco bug ID CSCvd36820.
This a
Cisco
Cisco IOS and IOS XE Software Smart Install Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0156 Cisco IOS and IOS XE Software Smart Install Denial of Service Vulnerability
CVE-2018-0156: Cisco IOS and IOS XE Software Smart Install Denial of Service Vulnerability
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted packet to an affected device on TCP port 4786. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-399, CWE-399
Bug IDs: CSCvd40673, CSCvd36820, CSCvd36820, CSCvd36820
GHSA
GHSA-25w3-v3vx-g29w: A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigge
ghsa_unreviewed·2022-05-13
CVE-2018-0156 [HIGH] CWE-20 GHSA-25w3-v3vx-g29w: A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigge
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted packet to an affected device on TCP port 4786. Only Smart Install client switches are affected. Cisco devices that are configured as a Smart Install director are not affected by this vulnerability. Cisco Bug IDs: CSCvd40673.
VulnCheck
Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability
vulncheck·2018·CVSS 7.5
CVE-2018-0156 [HIGH] CWE-399 Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability
Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial-of-service (DoS) condition.
Affected: Cisco IOS and IOS XE Software
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-20180328-smi.html
Remediation Due: 2022-03-17
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/103569http://www.securitytracker.com/id/1040596https://ics-cert.us-cert.gov/advisories/ICSA-18-107-04https://ics-cert.us-cert.gov/advisories/ICSA-18-107-05https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smihttp://www.securityfocus.com/bid/103569http://www.securitytracker.com/id/1040596https://ics-cert.us-cert.gov/advisories/ICSA-18-107-04https://ics-cert.us-cert.gov/advisories/ICSA-18-107-05https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smihttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-0156
2018-03-28
Published
2022-03-03
Added to CISA KEV
Exploited in the wild