CVE-2018-0167 is a critical vulnerability affecting Cisco IOS, IOS XE, and IOS XR Software, specifically within the Link Layer Discovery Protocol (LLDP) subsystem. It involves multiple buffer overflow flaws that can be exploited by an unauthenticated, adjacent attacker. This vulnerability carries a high CVSS score of 8.8, indicating a severe risk of denial of service or arbitrary code execution with elevated privileges. Notably, it is listed in CISA's KEV catalog, confirming active exploitation, though public exploit intelligence tools like Metasploit and ExploitDB do not currently list specific exploits. Despite the lack of media coverage, there is significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.2.0.baseCPE matchmatch criteria | cpe:2.3:o:cisco:ios:5.2.0.base:*:*:*:*:*:*:* | ||
5.2.0.baseCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:5.2.0.base:*:*:*:*:*:*:* | ||
>= 4.1, < 5.1.3CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xr:*:*:*:*:*:*:*:* | ||
<= 15.6.3m1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:* | ||
<= 15.6.3m1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.