CVE-2018-0159 is a denial-of-service vulnerability affecting Cisco IOS and IOS XE Software due to improper validation of Internet Key Exchange Version 1 (IKEv1) packets. An unauthenticated, remote attacker can exploit this by sending crafted IKEv1 packets during negotiation, causing the device to reload. With a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network with no user interaction, leading to a complete loss of availability. This CVE is listed in CISA's KEV catalog, indicating active exploitation, though no public exploit code or significant community discussion has been identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.3\(3\)sCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.3\(3\)s:*:*:*:*:*:*:* | ||
15.3\(3\)sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:15.3\(3\)s:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.