cbcvebase.
CVE-2018-0156
published 2018-03-28

CVE-2018-0156: A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a…

PriorityP180high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-17
Exploited in the wild
EPSS
8.30%
94.3th percentile
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted packet to an affected device on TCP port 4786. Only Smart Install client switches are affected. Cisco devices that are configured as a Smart Install director are not affected by this vulnerability. Cisco Bug IDs: CSCvd40673.

Affected

5 ranges
VendorProductVersion rangeFixed in
ciscoios
ciscoios
ciscoios_and_ios_xe
ciscoios_xe
ciscoios_xe

Detection & IOCsextracted from sources · hover to see the quote

portTCP/4786
  • Monitor and alert on inbound TCP connections to port 4786 (Cisco Smart Install) from untrusted/external sources, as exploitation involves sending a crafted packet to this port.
  • Only Smart Install client switches are affected; Smart Install director-configured devices are not. Focus detection on client-role Cisco IOS/IOS XE switches exposed on TCP/4786.
  • Smart Install client functionality is enabled by default on unpatched switches; inventory and identify all switches running Cisco IOS Software releases that have not been updated to address Cisco bug ID CSCvd36820 as high-priority detection targets.
  • ·No workarounds are available for this vulnerability; patching is the only remediation. Disabling or blocking Smart Install (TCP/4786) where not needed can reduce attack surface.
  • ·Smart Install client is enabled by default on affected unpatched Cisco IOS switches, meaning devices may be unknowingly exposed without explicit configuration.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vulncheck7.5HIGH
cisa7.5HIGH
vendor_cisco8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.