CVE-2018-0171 is a critical vulnerability in the Smart Install feature of Cisco IOS and IOS XE Software, stemming from improper packet data validation. An unauthenticated, remote attacker can exploit this by sending a crafted Smart Install message to TCP port 4786. This can lead to a denial of service (DoS) through device reload or indefinite loops, or allow arbitrary code execution due to a buffer overflow. The vulnerability carries a CVSS score of 9.8 (Critical), indicating a network-based attack with low complexity and no user interaction required, resulting in complete compromise of confidentiality, integrity, and availability. Its EPSS score of 0.93123 further highlights its high exploitability. CVE-2018-0171 is actively exploited in the wild, as confirmed by its presence in the KEV catalog. While no Metasploit or Nuclei modules are publicly available, a proof-of-concept crash exploit (EDB-44451) exists on ExploitDB. The vulnerability has garnered significant community discussion and media coverage, including reports of nation-state actors leveraging it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.2\(5\)eCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(5\)e:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.