CVE-2018-0476 is a denial-of-service vulnerability in Cisco IOS XE Software, specifically within the NAT SIP ALG. An unauthenticated, remote attacker can trigger a device reload by sending specially crafted SIP packets through a device performing NAT for SIP, leading to a DoS condition. This vulnerability has a CVSS score of 5.9 (Medium), indicating a network-based attack with high attack complexity and high impact on availability. While there is no known exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, there has been some community discussion and media coverage, suggesting awareness of the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.5\(3\)s5.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:15.5\(3\)s5.1:*:*:*:*:*:*:* | ||
15.5\(3\)s6.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:15.5\(3\)s6.1:*:*:*:*:*:*:* | ||
16.6.2CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:16.6.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.