CVE-2018-0180
published 2018-03-28CVE-2018-0180: Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a…
PriorityP275medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-17
Exploited in the wild
EPSS
5.03%
91.3th percentile
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Cisco Bug IDs: CSCuy32360, CSCuz60599.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target the Login Enhancements (Login Block) feature of Cisco IOS Software; unauthenticated remote exploitation triggers a system reload (DoS). Focus detection on anomalous login-block-related traffic to affected IOS devices. ↗
- →Scope detection to Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later; alert on unexpected device reloads on hosts running these versions with Login Block configured. ↗
- →Track Cisco Bug IDs CSCuy32360 and CSCuz60599 for patch status; both bugs are associated with this Login Block DoS attack surface. ↗
- ·No workarounds address both vulnerabilities simultaneously; patching per vendor instructions is the only complete remediation. ↗
- ·The vulnerability is only exploitable when the Login Enhancements (Login Block) feature is enabled on the affected IOS device; review device configurations for 'login block-for' commands to assess exposure. ↗
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vulncheck5.9MEDIUM
cisa5.9MEDIUM
vendor_cisco6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco IOS Software Denial-of-Service Vulnerability
cisa·2022-03-03·CVSS 5.9
CVE-2018-0180 [MEDIUM] CWE-399 Cisco IOS Software Denial-of-Service Vulnerability
Vulnerability: Cisco IOS Software Denial-of-Service Vulnerability
Affected: Cisco IOS Software
A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-0180
Remediation Due Date: 2022-03-17
Cisco
Cisco IOS Software Login Enhancements Login Block Denial of Service Vulnerabilities
vendor_cisco·2018-03-28·CVSS 6.8
CVE-2018-0179 [MEDIUM] CWE-399 Cisco IOS Software Login Enhancements Login Block Denial of Service Vulnerabilities
Cisco IOS Software Login Enhancements Login Block Denial of Service Vulnerabilities
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.
For more information about these vulnerabilities, see the Details section of this security advisory.
There are no workarounds that address both vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-slogin
Cisco
Cisco IOS Software Login Enhancements Login Block Denial of Service Vulnerabilities
vendor_cisco·CVSS 3.0
CVE-2018-0180 Cisco IOS Software Login Enhancements Login Block Denial of Service Vulnerabilities
CVE-2018-0180: Cisco IOS Software Login Enhancements Login Block Denial of Service Vulnerabilities
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. For more information about these vulnerabilities, see the
CVSS: 3.0
CWE: CWE-399, CWE-399
Bug IDs: CSCuy32360, CSCuz60599, CSCuy32360, CSCuz60599, CSCuy32360
GHSA
GHSA-rfg9-33h6-7pq5: Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trig
ghsa_unreviewed·2022-05-13
CVE-2018-0180 [HIGH] GHSA-rfg9-33h6-7pq5: Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trig
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Cisco Bug IDs: CSCuy32360, CSCuz60599.
VulnCheck
Cisco IOS Software Denial-of-Service Vulnerability
vulncheck·2018·CVSS 5.9
CVE-2018-0180 [MEDIUM] CWE-399 Cisco IOS Software Denial-of-Service Vulnerability
Cisco IOS Software Denial-of-Service Vulnerability
A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.
Affected: Cisco IOS Software
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-20180328-slogin.html
Remediation Due: 2022-03-17
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/103556https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-sloginhttp://www.securityfocus.com/bid/103556https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-sloginhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-0180
2018-03-28
Published
2022-03-03
Added to CISA KEV
Exploited in the wild