CVE-2018-0161 is a denial-of-service vulnerability in the SNMP subsystem of Cisco IOS Software, affecting specific Cisco Catalyst 2960-L and Digital Building Series Switches. An authenticated, remote attacker can trigger a device restart by sending an SNMP GET request for the ciscoFlashMIB object ID. Rated Medium (CVSS 6.3), this vulnerability has a network attack vector with high attack complexity, leading to high availability impact. It is actively exploited in the wild, as indicated by its presence in the KEV catalog, despite a lack of public exploit code in Metasploit or ExploitDB, and has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.2\(5\)eCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(5\)e:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.