peter bassill · operator
$ cve CVE-2018-0158 JSON

CVE-2018-0158 KEV

8.6
HIGH · CVSS 3.1 · EPSS 7.2% (pctl 94)

Patch first

On CISA KEV — known exploited in the wild, due 2022-03-17.

Description

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain IKEv2 packets. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device to be processed. A successful exploit could cause an affected device to continuously consume memory and eventually reload, resulting in a DoS condition. Cisco Bug IDs: CSCvf22394.

Scoring

CVSS8.6 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
EPSS7.19% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-20
On CISA KEVyes — remediate by 2022-03-17
Public exploitnone known
Published2018-03-28
Last modified2026-06-17

CISA KEV

NameCisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability
Added2022-03-03
Due2022-03-17
Vendor / productCisco / IOS Software and Cisco IOS XE Software
Ransomware usenone reported

Affected (12)

VendorProduct
ciscoasr 1001-hx
ciscoasr 1001-x
ciscoasr 1002-hx
ciscoasr 1002-x
ciscoasr 1004
ciscoasr 1006
ciscoasr 1006-x
ciscoasr 1009-x
ciscoasr 1013
ciscoios
ciscoios xe
rockwellautomationallen-bradley stratix 5900

References

→ the Explorer  ·  watch your stack  ·  NVD