cbcvebase.
CVE-2018-0175
published 2018-03-28

CVE-2018-0175: Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could…

PriorityP180high8CVSS 3.1
AVAACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-17
Exploited in the wild
EPSS
3.55%
88.0th percentile
Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCvd73664.

Affected

10 ranges
VendorProductVersion rangeFixed in
ciscoios<= 15.2\(4a\)ea5
ciscoios<= 15.2\(6\)e0a
ciscoios<= 15.6.3m1
ciscoios
ciscoios_ios_xe_and_ios_xr
ciscoios_xe<= 15.2\(4a\)ea5
ciscoios_xe<= 15.2\(6\)e0a
ciscoios_xe<= 15.6.3m1
ciscoios_xe
ciscoios_xr

Detection & IOCsextracted from sources · hover to see the quote

portUDP 18999
  • Cisco has released Snort Rules 46110 and 46111 to help address CVE-2018-0158 and CVE-2018-0151 (related LLDP bundle); no dedicated Snort rule is cited for CVE-2018-0175 specifically, but the LLDP advisory bundle rules may provide partial coverage.
  • CVE-2018-0175 is a format string vulnerability triggered via crafted LLDP frames from an adjacent (Layer 2) attacker; monitor for anomalous LLDP traffic on network segments containing Cisco IOS, IOS XE, or IOS XR devices.
  • Cisco Bug IDs CSCvd73664, CSCuo17183, and CSCvd73487 are associated with this vulnerability and can be used to cross-reference affected software versions in Cisco's advisory tooling.
  • ·CVE-2018-0175 has no specific mitigations available; the only remediation is patching to an unaffected Cisco IOS/IOS XE/IOS XR release.
  • ·Allen-Bradley Stratix 5900 Services Router version 15.6.3M1 and earlier is confirmed affected as it runs a vulnerable version of Cisco IOS or IOS XE.
  • ·No known public exploits specifically target CVE-2018-0175 at time of advisory publication, though it is listed in CISA KEV.

CVSS provenance

nvdv3.18.0HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.9HIGHAV:A/AC:M/Au:N/C:C/I:C/A:C
vulncheck8.0HIGH
cisa8.0HIGH
vendor_cisco8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.