CVE-2018-0175
published 2018-03-28CVE-2018-0175: Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could…
PriorityP180high8CVSS 3.1
AVAACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-17
Exploited in the wild
EPSS
3.55%
88.0th percentile
Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCvd73664.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | <= 15.2\(4a\)ea5 | — |
| cisco | ios | <= 15.2\(6\)e0a | — |
| cisco | ios | <= 15.6.3m1 | — |
| cisco | ios | — | — |
| cisco | ios_ios_xe_and_ios_xr | — | — |
| cisco | ios_xe | <= 15.2\(4a\)ea5 | — |
| cisco | ios_xe | <= 15.2\(6\)e0a | — |
| cisco | ios_xe | <= 15.6.3m1 | — |
| cisco | ios_xe | — | — |
| cisco | ios_xr | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Cisco has released Snort Rules 46110 and 46111 to help address CVE-2018-0158 and CVE-2018-0151 (related LLDP bundle); no dedicated Snort rule is cited for CVE-2018-0175 specifically, but the LLDP advisory bundle rules may provide partial coverage. ↗
- →CVE-2018-0175 is a format string vulnerability triggered via crafted LLDP frames from an adjacent (Layer 2) attacker; monitor for anomalous LLDP traffic on network segments containing Cisco IOS, IOS XE, or IOS XR devices. ↗
- →Cisco Bug IDs CSCvd73664, CSCuo17183, and CSCvd73487 are associated with this vulnerability and can be used to cross-reference affected software versions in Cisco's advisory tooling. ↗
- ·CVE-2018-0175 has no specific mitigations available; the only remediation is patching to an unaffected Cisco IOS/IOS XE/IOS XR release. ↗
- ·Allen-Bradley Stratix 5900 Services Router version 15.6.3M1 and earlier is confirmed affected as it runs a vulnerable version of Cisco IOS or IOS XE. ↗
- ·No known public exploits specifically target CVE-2018-0175 at time of advisory publication, though it is listed in CISA KEV. ↗
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.9HIGHAV:A/AC:M/Au:N/C:C/I:C/A:C
vulncheck8.0HIGH
cisa8.0HIGH
vendor_cisco8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
cisa·2022-03-03·CVSS 8.0
CVE-2018-0175 [HIGH] CWE-119 Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
Vulnerability: Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
Affected: Cisco IOS, XR, and XE Software
Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-0175
Remediation Due Date: 2022-03-17
CISA ICS
Rockwell Automation Stratix Industrial Managed Ethernet Switch
cisa_ics·2018-04-25·CVSS 9.8
[CRITICAL] Rockwell Automation Stratix Industrial Managed Ethernet Switch
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix Industrial Managed Ethernet Switch
Last RevisedApril 25, 2018
Alert CodeICSA-18-107-05
## 1. EXECUTIVE SUMMARY
-
CVSS v3 9.8
- ATTENTION: Exploitable remotely/low skill level to exploit.
- Vendor: Rockwell Automation
- Equipment: Allen-Bradley Stratix Industrial Managed Ethernet Switch
- Vulnerabilities: Improper Input Validation, Resource Management Errors, 7PK – Errors, Improper Restriction of Operations within the Bounds of a Memory Buffer, Use of Externally-Controlled Format String.
## 2. RISK EVALUATION
Successful exploitation of these vuln
CISA ICS
Rockwell Automation Stratix and ArmorStratix Switches
cisa_ics·2018-04-25
Rockwell Automation Stratix and ArmorStratix Switches
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix and ArmorStratix Switches
Last RevisedApril 25, 2018
Alert CodeICSA-18-107-04
## 1. EXECUTIVE SUMMARY
-
CVSS v3 9.8
- ATTENTION: Exploitable remotely/low skill level to exploit.
- Vendor: Rockwell Automation
- Equipment: Allen-Bradley Stratix and ArmorStratix Switches
- Vulnerabilities: Improper Input Validation, Resource Management Errors, Improper Restriction of Operations within the Bounds of a Memory Buffer, Use of Externally-Controlled Format String.
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could result in loss
CISA ICS
Rockwell Automation Stratix Services Router
cisa_ics·2018-04-25·CVSS 8.6
[HIGH] Rockwell Automation Stratix Services Router
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix Services Router
Last RevisedApril 25, 2018
Alert CodeICSA-18-107-03
## 1. EXECUTIVE SUMMARY
-
CVSS v3 9.8
- ATTENTION: Exploitable remotely/low skill level to exploit.
- Vendor: Rockwell Automation
- Equipment: Allen-Bradley Stratix 5900 Services Router
- Vulnerabilities: Improper Input Validation, Improper Restriction of Operations within the Bounds of a Memory Buffer, Use of Externally-Controlled Format String.
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could result in loss of availability, confidentiality, and/or i
Cisco
Cisco IOS, IOS XE, and IOS XR Software Link Layer Discovery Protocol Buffer Overflow Vulnerabilities
vendor_cisco·2018-03-28·CVSS 8.8
CVE-2018-0167 [HIGH] CWE-119 Cisco IOS, IOS XE, and IOS XR Software Link Layer Discovery Protocol Buffer Overflow Vulnerabilities
Cisco IOS, IOS XE, and IOS XR Software Link Layer Discovery Protocol Buffer Overflow Vulnerabilities
Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-lldp
Th
Cisco
Cisco IOS, IOS XE, and IOS XR Software Link Layer Discovery Protocol Buffer Overflow Vulnerabilities
vendor_cisco·CVSS 3.0
CVE-2018-0175 Cisco IOS, IOS XE, and IOS XR Software Link Layer Discovery Protocol Buffer Overflow Vulnerabilities
CVE-2018-0175: Cisco IOS, IOS XE, and IOS XR Software Link Layer Discovery Protocol Buffer Overflow Vulnerabilities
Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. For more information about these vulnerabilities, see the
CVSS: 3.0
CWE: CWE-119, CWE-134, CWE-119, CWE-134
Bug IDs: CSCuo17183, CSCvd73487, CSCvd73664, CSCvd73487, CSCuo17183
GHSA
GHSA-f6hc-7357-x73w: Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Softw
ghsa_unreviewed·2022-05-13
CVE-2018-0175 [HIGH] CWE-119 GHSA-f6hc-7357-x73w: Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Softw
Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCvd73664.
VulnCheck
Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
vulncheck·2018·CVSS 8.0
CVE-2018-0175 [HIGH] CWE-119 Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device.
Affected: Cisco IOS, XR, and XE Software
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-20180328-lldp.html
Remediation Due: 2022-03-17
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/103564http://www.securitytracker.com/id/1040586https://ics-cert.us-cert.gov/advisories/ICSA-18-107-03https://ics-cert.us-cert.gov/advisories/ICSA-18-107-04https://ics-cert.us-cert.gov/advisories/ICSA-18-107-05https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-lldphttp://www.securityfocus.com/bid/103564http://www.securitytracker.com/id/1040586https://ics-cert.us-cert.gov/advisories/ICSA-18-107-03https://ics-cert.us-cert.gov/advisories/ICSA-18-107-04https://ics-cert.us-cert.gov/advisories/ICSA-18-107-05https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-lldphttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-0175
2018-03-28
Published
2022-03-03
Added to CISA KEV
Exploited in the wild