CVE-2018-0180 describes multiple denial-of-service vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software, specifically affecting devices running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. An unauthenticated, remote attacker can exploit these flaws to trigger a system reload. Rated with a CVSS score of 5.9 (Medium), the vulnerability has a network attack vector and high attack complexity, leading to a high availability impact. This CVE is actively exploited in the wild, as indicated by its presence in the KEV catalog, despite a lack of public exploit code in Metasploit, Nuclei, or ExploitDB. The vulnerability has garnered significant community discussion, with 10 mentions, but no media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.3\(00.00.19\)syCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.3\(00.00.19\)sy:*:*:*:*:*:*:* | ||
15.4\(01\)ia001.100CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.4\(01\)ia001.100:*:*:*:*:*:*:* | ||
15.6\(01.22\)tCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.6\(01.22\)t:*:*:*:*:*:*:* | ||
15.4\(03\)m4.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.4\(03\)m4.1:*:*:*:*:*:*:* | ||
15.4\(2\)cgCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.4\(2\)cg:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.