CVE-2018-0164 describes a vulnerability in Cisco IOS XE Software's Switch Integrated Security Features, allowing an unauthenticated, remote attacker to cause an interface queue wedge by sending crafted IPv6 packets. This affects Cisco cBR-8 Converged Broadband Routers, ASR 1000 Series Aggregation Services Routers, and Cloud Services Router 1000V Series when configured with IPv6. With a CVSS score of 8.6 (HIGH), the vulnerability has a network attack vector, low attack complexity, and high impact on availability, as it can disrupt network services. While observed on the cBR-8, the same code logic exists in other affected products. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.6\(2\)spCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:15.6\(2\)sp:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.