CVE-2018-0156 is a denial-of-service vulnerability affecting Cisco IOS and IOS XE Software, specifically devices configured as Smart Install clients. An unauthenticated, remote attacker can exploit this by sending a crafted packet to TCP port 4786, causing the device to reload. With a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network with low complexity and can lead to significant service disruption. This CVE is known to be actively exploited in the wild, as indicated by its presence in the KEV catalog and media coverage of real-world attacks, despite a lack of public exploit code in common repositories. Community discussion and media coverage suggest notable attention to this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.2\(2\)e4CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(2\)e4:*:*:*:*:*:*:* | ||
15.2\(2a\)jaCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(2a\)ja:*:*:*:*:*:*:* | ||
15.2\(2\)e4CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:15.2\(2\)e4:*:*:*:*:*:*:* | ||
15.2\(2a\)jaCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:15.2\(2a\)ja:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.