CVE-2018-0154 is a denial-of-service vulnerability in the crypto engine of Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software. An unauthenticated, remote attacker can exploit this by sending crafted VPN traffic, causing the device to hang or crash. With a CVSS score of 7.5 (High), it has a low attack complexity and requires no user interaction, leading to a complete loss of availability. This vulnerability is actively exploited and listed in CISA's KEV catalog, despite no public exploit code being readily available through Metasploit or ExploitDB. Community discussion is notably high, indicating significant interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:ios:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.