CVE-2018-0485 describes a denial-of-service vulnerability in Cisco Second Generation Integrated Services Routers (ISR G2) and the SM-1T3/E3 module on the Cisco 4451-X Integrated Services Router. This flaw, stemming from improper user input handling, allows an unauthenticated, remote attacker to cause a device reload by entering a specific string sequence via the module console. With a CVSS score of 8.6 (High), this vulnerability presents a significant risk due to its network-based attack vector and low complexity, leading to a complete loss of availability. While not listed in CISA's KEV catalog, there is no public exploit code available, and community discussion and media coverage are limited, suggesting it is not widely exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.6\(3\)mCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.6\(3\)m:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.