cbcvebase.
CVE-2018-0173
published 2018-03-28

CVE-2018-0173: A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4)…

PriorityP180high8.6CVSS 3.1
AVNACLPRNUINSCCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-17
Exploited in the wild
EPSS
7.76%
94.0th percentile
A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a Relay Reply denial of service (DoS) condition. The vulnerability exists because the affected software performs incomplete input validation of encapsulated option 82 information that it receives in DHCPOFFER messages from DHCPv4 servers. An attacker could exploit this vulnerability by sending a crafted DHCPv4 packet to an affected device, which the device would then forward to a DHCPv4 server. When the affected software processes the option 82 information that is encapsulated in the response from the server, an error could occur. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvg62754.

Affected

7 ranges
VendorProductVersion rangeFixed in
ciscoios<= 15.2\(6\)e0a
ciscoios<= 15.2\(4a\)ea5
ciscoios
ciscoios_and_ios_xe
ciscoios_xe<= 15.2\(6\)e0a
ciscoios_xe<= 15.2\(4a\)ea5
ciscoios_xe

Detection & IOCsextracted from sources · hover to see the quote

  • Trigger condition: crafted DHCPv4 packet with option 82 carrying an invalid (too long) length field, sent to a device acting as a DHCP relay agent, causing a bad memset size calculation and access violation on receipt of the DHCPOFFER response
  • Attack vector: the malicious packet must be a DHCPv4 packet forwarded by the relay agent to a DHCPv4 server; the vulnerability is triggered when the relay agent processes the encapsulated option 82 in the DHCPOFFER response from the server
  • Cisco Bug ID CSCvg62754 can be used to track vendor patches and correlate device logs or crash reports to this specific vulnerability
  • ·Vulnerability only affects devices with the DHCP relay agent configured (ip helper-address); devices not acting as a DHCPv4 relay agent are not affected
  • ·The vulnerability is triggered specifically during processing of DHCPOFFER messages (relay reply path), not during the initial client request forwarding path
  • ·No workarounds are available; only vendor software updates address this vulnerability

CVSS provenance

nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vulncheck8.6HIGH
cisa8.6HIGH
vendor_cisco8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.