CVE-2018-0158 is a denial-of-service vulnerability affecting the Internet Key Exchange Version 2 (IKEv2) module in Cisco IOS and IOS XE Software, as well as Rockwell Automation products. An unauthenticated, remote attacker can exploit this by sending crafted IKEv2 packets, leading to a memory leak and eventual device reload. With a CVSS score of 8.6 (HIGH), this vulnerability is easily exploitable over the network with low attack complexity, resulting in a complete loss of availability. This CVE is listed in CISA's KEV catalog, indicating active exploitation, despite a lack of public exploit code or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.5\(3\)s1.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.5\(3\)s1.1:*:*:*:*:*:*:* | ||
15.5\(3\)s1.2CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.5\(3\)s1.2:*:*:*:*:*:*:* | ||
15.5\(3\)s1.4CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.5\(3\)s1.4:*:*:*:*:*:*:* | ||
15.5\(3\)s1.5CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.5\(3\)s1.5:*:*:*:*:*:*:* | ||
15.5\(3\)s1.7CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.5\(3\)s1.7:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.