CVE-2018-0167
published 2018-03-28CVE-2018-0167: Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR…
PriorityP182high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-17
Exploited in the wild
EPSS
3.42%
87.6th percentile
Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCuo17183, CSCvd73487.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | <= 15.6.3m1 | — |
| cisco | ios | <= 15.2\(6\)e0a | — |
| cisco | ios | <= 15.2\(4a\)ea5 | — |
| cisco | ios | — | — |
| cisco | ios_ios_xe_and_ios_xr | — | — |
| cisco | ios_xe | <= 15.6.3m1 | — |
| cisco | ios_xe | <= 15.2\(6\)e0a | — |
| cisco | ios_xe | <= 15.2\(4a\)ea5 | — |
| cisco | ios_xe | — | — |
| cisco | ios_xr | >= 4.1 < 5.1.3 | 5.1.3 |
Detection & IOCsextracted from sources · hover to see the quote
- →Cisco has released Snort Rules 46110 and 46111 to help address CVE-2018-0158 and CVE-2018-0151 (co-disclosed in the same advisory bundle); no dedicated Snort rule is cited for CVE-2018-0167 specifically, but the LLDP subsystem buffer overflow (CVE-2018-0167) can be monitored via adjacent-layer LLDP traffic inspection. ↗
- →CVE-2018-0167 is exploitable only by an adjacent (Layer 2) unauthenticated attacker via crafted LLDP packets; detection should focus on anomalous LLDP frames on network segments hosting Cisco IOS/IOS XE/IOS XR devices. ↗
- →CVE-2018-0167 and CVE-2018-0175 have no specific mitigations; prioritize patching and monitor for unexpected device reloads or memory corruption symptoms on LLDP-enabled interfaces. ↗
- ·Allen-Bradley Stratix 5900 Services Router version 15.6.3M1 and earlier is confirmed affected as it runs a vulnerable version of Cisco IOS or IOS XE. ↗
- ·The vulnerability is tracked under Cisco Bug IDs CSCuo17183 and CSCvd73487; these IDs can be used to query Cisco's bug tracker for affected release trains. ↗
- ·No public exploits were known at time of advisory publication, but the CVE is listed in CISA's Known Exploited Vulnerabilities catalog with a remediation due date of 2022-03-17, indicating subsequent in-the-wild exploitation. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.3HIGHAV:A/AC:L/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
vendor_cisco8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
cisa·2022-03-03·CVSS 8.8
CVE-2018-0167 [HIGH] CWE-119 Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
Vulnerability: Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
Affected: Cisco IOS, XR, and XE Software
There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software which could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-0167
Remediation Due Date: 2022-03-17
CISA ICS
Rockwell Automation Stratix Industrial Managed Ethernet Switch
cisa_ics·2018-04-25·CVSS 9.8
[CRITICAL] Rockwell Automation Stratix Industrial Managed Ethernet Switch
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix Industrial Managed Ethernet Switch
Last RevisedApril 25, 2018
Alert CodeICSA-18-107-05
## 1. EXECUTIVE SUMMARY
-
CVSS v3 9.8
- ATTENTION: Exploitable remotely/low skill level to exploit.
- Vendor: Rockwell Automation
- Equipment: Allen-Bradley Stratix Industrial Managed Ethernet Switch
- Vulnerabilities: Improper Input Validation, Resource Management Errors, 7PK – Errors, Improper Restriction of Operations within the Bounds of a Memory Buffer, Use of Externally-Controlled Format String.
## 2. RISK EVALUATION
Successful exploitation of these vuln
CISA ICS
Rockwell Automation Stratix and ArmorStratix Switches
cisa_ics·2018-04-25
Rockwell Automation Stratix and ArmorStratix Switches
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix and ArmorStratix Switches
Last RevisedApril 25, 2018
Alert CodeICSA-18-107-04
## 1. EXECUTIVE SUMMARY
-
CVSS v3 9.8
- ATTENTION: Exploitable remotely/low skill level to exploit.
- Vendor: Rockwell Automation
- Equipment: Allen-Bradley Stratix and ArmorStratix Switches
- Vulnerabilities: Improper Input Validation, Resource Management Errors, Improper Restriction of Operations within the Bounds of a Memory Buffer, Use of Externally-Controlled Format String.
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could result in loss
CISA ICS
Rockwell Automation Stratix Services Router
cisa_ics·2018-04-25·CVSS 8.6
[HIGH] Rockwell Automation Stratix Services Router
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix Services Router
Last RevisedApril 25, 2018
Alert CodeICSA-18-107-03
## 1. EXECUTIVE SUMMARY
-
CVSS v3 9.8
- ATTENTION: Exploitable remotely/low skill level to exploit.
- Vendor: Rockwell Automation
- Equipment: Allen-Bradley Stratix 5900 Services Router
- Vulnerabilities: Improper Input Validation, Improper Restriction of Operations within the Bounds of a Memory Buffer, Use of Externally-Controlled Format String.
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could result in loss of availability, confidentiality, and/or i
Cisco
Cisco IOS, IOS XE, and IOS XR Software Link Layer Discovery Protocol Buffer Overflow Vulnerabilities
vendor_cisco·2018-03-28·CVSS 8.8
CVE-2018-0167 [HIGH] CWE-119 Cisco IOS, IOS XE, and IOS XR Software Link Layer Discovery Protocol Buffer Overflow Vulnerabilities
Cisco IOS, IOS XE, and IOS XR Software Link Layer Discovery Protocol Buffer Overflow Vulnerabilities
Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-lldp
Th
Cisco
Cisco IOS, IOS XE, and IOS XR Software Link Layer Discovery Protocol Buffer Overflow Vulnerabilities
vendor_cisco·CVSS 3.0
CVE-2018-0167 Cisco IOS, IOS XE, and IOS XR Software Link Layer Discovery Protocol Buffer Overflow Vulnerabilities
CVE-2018-0167: Cisco IOS, IOS XE, and IOS XR Software Link Layer Discovery Protocol Buffer Overflow Vulnerabilities
Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. For more information about these vulnerabilities, see the
CVSS: 3.0
CWE: CWE-119, CWE-134, CWE-119, CWE-134
Bug IDs: CSCuo17183, CSCvd73487, CSCvd73664, CSCvd73487, CSCuo17183
GHSA
GHSA-h85m-74j9-4r6m: Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco
ghsa_unreviewed·2022-05-13
CVE-2018-0167 [HIGH] CWE-119 GHSA-h85m-74j9-4r6m: Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco
Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCuo17183, CSCvd73487.
VulnCheck
Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
vulncheck·2018·CVSS 8.8
CVE-2018-0167 [HIGH] CWE-119 Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software which could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code.
Affected: Cisco IOS, XR, and XE Software
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-20180328-lldp.html
Remediation Due: 2022-03-17
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/103564http://www.securitytracker.com/id/1040586https://ics-cert.us-cert.gov/advisories/ICSA-18-107-03https://ics-cert.us-cert.gov/advisories/ICSA-18-107-04https://ics-cert.us-cert.gov/advisories/ICSA-18-107-05https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-lldphttp://www.securityfocus.com/bid/103564http://www.securitytracker.com/id/1040586https://ics-cert.us-cert.gov/advisories/ICSA-18-107-03https://ics-cert.us-cert.gov/advisories/ICSA-18-107-04https://ics-cert.us-cert.gov/advisories/ICSA-18-107-05https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-lldphttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-0167
2018-03-28
Published
2022-03-03
Added to CISA KEV
Exploited in the wild