cbcvebase.
CVE-2018-0171
published 2018-03-28

CVE-2018-0171: A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a…

PriorityP197critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
99.51%
99.9th percentile
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute arbitrary code on an affected device. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted Smart Install message to an affected device on TCP port 4786. A successful exploit could allow the attacker to cause a buffer overflow on the affected device, which could have the following impacts: Triggering a reload of the device, Allowing the attacker to execute arbitrary code on the device, Causing an indefinite loop on the affected device that triggers a watchdog crash. Cisco Bug IDs: CSCvg76186.

Affected

2 ranges
VendorProductVersion rangeFixed in
ciscoios
ciscoios_and_ios_xe

Detection & IOCsextracted from sources · hover to see the quote

portTCP/4786
commandMonitor capture CAP export ftp://
  • Monitor for inbound TCP connections to port 4786 (Cisco Smart Install) from untrusted/external sources; crafted Smart Install messages on this port are the exploit vector for CVE-2018-0171.
  • Detect SNMP traffic with community strings 'anonymous' or 'public' with read-write permissions, which Static Tundra has used for initial access and lateral movement.
  • Look for SSH daemons started on non-standard high ports (e.g., port 57722) within Cisco Guest Shell or underlying Linux shell, indicating persistent backdoor access.
  • Monitor for the presence of a GO-compiled ELF x86-64 binary (JumbledPath) in actor-configured Guestshell instances on Cisco Nexus devices; this tool performs remote packet capture and log clearing.
  • Monitor syslog and AAA logs for gaps or decreases in normal logging events, which may indicate the threat actor is clearing logs (.bash_history, auth.log, lastlog, wtmp, btmp) to cover tracks.
  • Detect unexpected AAA/TACACS+ server IP address changes in device running configurations, which the threat actor uses to bypass access control systems.
  • Use Tenable plugin 105161 to detect Cisco devices with Smart Install enabled and exposed on the network.
  • Profile Cisco network devices via NetFlow and port scanning for new ports opening (especially non-standard SSH ports) or unexpected traffic sourced from loopback interfaces, which the threat actor modifies to bypass ACLs.
  • ·CVE-2018-0171 exploitation was confirmed in only one Salt Typhoon incident by Cisco Talos; all other Salt Typhoon initial accesses investigated used stolen legitimate credentials, not this CVE.
  • ·GreyNoise explicitly does not attribute the two malicious IPs exploiting CVE-2018-0171 to Salt Typhoon — only confirming exploitation is occurring.
  • ·Static Tundra (Russian FSB-linked) exploitation of CVE-2018-0171 is assessed with moderate confidence to use bespoke automated tooling against target IPs likely sourced from Shodan or Censys scan data.
  • ·Cisco Talos has not identified evidence confirming Salt Typhoon abused CVE-2023-20198, CVE-2023-20273, or CVE-2024-20399 beyond CVE-2018-0171, despite public reports claiming otherwise.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_cisco9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.