cbcvebase.
CVE-2018-0180
published 2018-03-28

CVE-2018-0180: Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a…

PriorityP275medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-17
Exploited in the wild
EPSS
5.03%
91.3th percentile
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Cisco Bug IDs: CSCuy32360, CSCuz60599.

Affected

8 ranges
VendorProductVersion rangeFixed in
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios

Detection & IOCsextracted from sources · hover to see the quote

  • Target the Login Enhancements (Login Block) feature of Cisco IOS Software; unauthenticated remote exploitation triggers a system reload (DoS). Focus detection on anomalous login-block-related traffic to affected IOS devices.
  • Scope detection to Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later; alert on unexpected device reloads on hosts running these versions with Login Block configured.
  • Track Cisco Bug IDs CSCuy32360 and CSCuz60599 for patch status; both bugs are associated with this Login Block DoS attack surface.
  • ·No workarounds address both vulnerabilities simultaneously; patching per vendor instructions is the only complete remediation.
  • ·The vulnerability is only exploitable when the Login Enhancements (Login Block) feature is enabled on the affected IOS device; review device configurations for 'login block-for' commands to assess exposure.

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vulncheck5.9MEDIUM
cisa5.9MEDIUM
vendor_cisco6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.