CVE-2018-0131 is a medium-severity vulnerability affecting Cisco IOS and IOS XE Software, specifically within their Internet Key Exchange Version 1 (IKEv1) implementation when using RSA-encrypted nonces. The flaw allows an unauthenticated, remote attacker to obtain encrypted nonces due to incorrect handling of decryption failures. Exploitation requires high attack complexity, but successful execution could lead to the disclosure of sensitive cryptographic material. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating awareness despite its inactive status on the CISA KEV list.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.5\(3\)sCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.5\(3\)s:*:*:*:*:*:*:* | ||
15.5\(3\)sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:15.5\(3\)s:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.