CVE-2018-0473 describes a denial-of-service vulnerability in the Precision Time Protocol (PTP) subsystem of Cisco IOS Software. An unauthenticated, remote attacker can exploit this by sending specially crafted PTP packets, leading to time synchronization issues across the network. This vulnerability carries a high CVSS score of 8.6, indicating a network-based attack with low complexity and high impact on availability. While not actively exploited in the wild and lacking public exploit code, it has garnered some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.2\(4\)eCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(4\)e:*:*:*:*:*:*:* | ||
15.2\(5\)CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(5\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.