peter bassill · operator
$ cve CVE-2018-0167 JSON

CVE-2018-0167 KEV

8.8
HIGH · CVSS 3.1 · EPSS 3.4% (pctl 88)

Patch first

On CISA KEV — known exploited in the wild, due 2022-03-17.

Description

Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCuo17183, CSCvd73487.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.35% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-119
On CISA KEVyes — remediate by 2022-03-17
Public exploitnone known
Published2018-03-28
Last modified2026-06-17

CISA KEV

NameCisco IOS, XR, and XE Software Buffer Overflow Vulnerability
Added2022-03-03
Due2022-03-17
Vendor / productCisco / IOS, XR, and XE Software
Ransomware usenone reported

Affected (18)

VendorProduct
ciscoasr 9001
ciscoasr 9006
ciscoasr 9010
ciscoasr 9904
ciscoasr 9906
ciscoasr 9910
ciscoasr 9912
ciscoasr 9922
ciscoios
ciscoios xe
ciscoios xr
rockwellautomationallen-bradley armorstratix 5700
rockwellautomationallen-bradley stratix 5400
rockwellautomationallen-bradley stratix 5410
rockwellautomationallen-bradley stratix 5700
rockwellautomationallen-bradley stratix 5900
rockwellautomationallen-bradley stratix 8000
rockwellautomationallen-bradley stratix 8300

References

→ the Explorer  ·  watch your stack  ·  NVD