CVE-2018-0151 is a critical buffer overflow vulnerability in the Quality of Service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software. It allows an unauthenticated, remote attacker to cause a denial of service (DoS) or execute arbitrary code with elevated privileges by sending specially crafted packets to UDP port 18999. With a CVSS score of 9.8 (Critical), this vulnerability has a low attack complexity and can lead to complete compromise of the affected device. This flaw is actively exploited in the wild, as indicated by its presence in CISA's KEV catalog, and has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
16.5.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:16.5.1:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.