cbcvebase.
CVE-2018-0167
published 2018-03-28

CVE-2018-0167: Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR…

PriorityP182high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-17
Exploited in the wild
EPSS
3.42%
87.6th percentile
Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCuo17183, CSCvd73487.

Affected

10 ranges
VendorProductVersion rangeFixed in
ciscoios<= 15.6.3m1
ciscoios<= 15.2\(6\)e0a
ciscoios<= 15.2\(4a\)ea5
ciscoios
ciscoios_ios_xe_and_ios_xr
ciscoios_xe<= 15.6.3m1
ciscoios_xe<= 15.2\(6\)e0a
ciscoios_xe<= 15.2\(4a\)ea5
ciscoios_xe
ciscoios_xr>= 4.1 < 5.1.35.1.3

Detection & IOCsextracted from sources · hover to see the quote

portUDP 18999
  • Cisco has released Snort Rules 46110 and 46111 to help address CVE-2018-0158 and CVE-2018-0151 (co-disclosed in the same advisory bundle); no dedicated Snort rule is cited for CVE-2018-0167 specifically, but the LLDP subsystem buffer overflow (CVE-2018-0167) can be monitored via adjacent-layer LLDP traffic inspection.
  • CVE-2018-0167 is exploitable only by an adjacent (Layer 2) unauthenticated attacker via crafted LLDP packets; detection should focus on anomalous LLDP frames on network segments hosting Cisco IOS/IOS XE/IOS XR devices.
  • CVE-2018-0167 and CVE-2018-0175 have no specific mitigations; prioritize patching and monitor for unexpected device reloads or memory corruption symptoms on LLDP-enabled interfaces.
  • ·Allen-Bradley Stratix 5900 Services Router version 15.6.3M1 and earlier is confirmed affected as it runs a vulnerable version of Cisco IOS or IOS XE.
  • ·The vulnerability is tracked under Cisco Bug IDs CSCuo17183 and CSCvd73487; these IDs can be used to query Cisco's bug tracker for affected release trains.
  • ·No public exploits were known at time of advisory publication, but the CVE is listed in CISA's Known Exploited Vulnerabilities catalog with a remediation due date of 2022-03-17, indicating subsequent in-the-wild exploitation.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.3HIGHAV:A/AC:L/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
vendor_cisco8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.