CVE-2018-0174 is a high-severity denial-of-service vulnerability affecting Cisco IOS and IOS XE Software, as well as Rockwell Automation products. It arises from incomplete input validation of DHCPv4 option 82 information, allowing an unauthenticated, remote attacker to cause a device reload. With a CVSS score of 8.6, this vulnerability is easily exploitable over the network with low attack complexity, leading to a complete loss of availability. Notably, this CVE is listed in the KEV catalog, indicating active exploitation, despite a lack of public exploit code or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.2\(33\)sre7aCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(33\)sre7a:*:*:*:*:*:*:* | ||
12.2\(33\)sre7aCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:12.2\(33\)sre7a:*:*:*:*:*:*:* | ||
<= 15.2\(4a\)ea5CPE matchmatch criteria | cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:* | ||
<= 15.2\(4a\)ea5CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:* | ||
<= 15.2\(6\)e0aCPE matchmatch criteria | cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
[R1] Cisco IOS and IOS XE Multiple Memory Corruption Vulnerabilities
Mar 28, 2018[R1] Cisco IOS and IOS XE Multiple Memory Corruption Vulnerabilities
Mar 28, 2018Cisco IOS and IOS XE Multiple Memory Corruption Vulnerabilities
Mar 28, 2018