cbcvebase.
CVE-2018-0158
published 2018-03-28

CVE-2018-0158: A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote…

PriorityP277high8.6CVSS 3.1
AVNACLPRNUINSCCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-17
Exploited in the wild
EPSS
7.33%
93.7th percentile
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain IKEv2 packets. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device to be processed. A successful exploit could cause an affected device to continuously consume memory and eventually reload, resulting in a DoS condition. Cisco Bug IDs: CSCvf22394.

Affected

21 ranges
VendorProductVersion rangeFixed in
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios_and_ios_xe
ciscoios_xe
ciscoios_xe
ciscoios_xe
ciscoios_xe
ciscoios_xe
ciscoios_xe
ciscoios_xe
ciscoios_xe
ciscoios_xe
ciscoios_xe

Detection & IOCsextracted from sources · hover to see the quote

portUDP 18999
snort
Snort Rule 46110
snort
Snort Rule 46111
  • Detect crafted IKEv2 packets sent to an affected Cisco IOS/IOS XE device; Cisco has released dedicated Snort rules (46110, 46111) for this purpose.
  • Monitor for continuous memory consumption and unexpected device reloads on Cisco IOS/IOS XE devices as indicators of active exploitation of CVE-2018-0158.
  • ·Allen-Bradley Stratix 5900 Services Router version 15.6.3M1 and earlier is confirmed affected as it runs a vulnerable version of Cisco IOS/IOS XE.
  • ·There are no workarounds that address CVE-2018-0158; software update is the only remediation.
  • ·The vulnerability is tracked under Cisco Bug ID CSCvf22394.

CVSS provenance

nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vulncheck8.6HIGH
cisa8.6HIGH
vendor_cisco8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.