HIGH🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2018-0154

CVSS 7.5v3.1pub. 2018-03-28upd. 2026-01-13

A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient handling of VPN traffic by the affected device. An attacker could exploit this vulnerability by sending crafted VPN traffic to an affected device. A successful exploit could allow the attacker to cause the affected device to hang or crash, resulting in a DoS condition. Cisco Bug IDs: CSCvd39267.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Cisco 1000 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1100 4g\/6g Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1100 4g Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1100 4gltegb Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1100 4gltena Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1100 4p Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1100 6g Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1100 8p Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1100 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1100 Lte Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1101 4p Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1101 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1109 2p Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1109 4p Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1109 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1111x 8p Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1111x Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 111x Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1120 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1131 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1160 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1801 Integrated Service Router

    HW
    Cisco
    all versions
  • Cisco 1802 Integrated Service Router

    HW
    Cisco
    all versions
  • Cisco 1803 Integrated Service Router

    HW
    Cisco
    all versions
  • Cisco 1811 Integrated Service Router

    HW
    Cisco
    all versions
  • Cisco 1812 Integrated Service Router

    HW
    Cisco
    all versions
  • Cisco 1841 Integrated Service Router

    HW
    Cisco
    all versions
  • Cisco 1861 Integrated Service Router

    HW
    Cisco
    all versions
  • Cisco 1905 Integrated Services Router

    HW
    Cisco
    all versions
  • Cisco 1906c Integrated Services Router

    HW
    Cisco
    all versions

CISA KEV — detailsi

Vendori
Cisco
Producti
IOS Software
Added to KEVi
March 3, 2022
Remediation deadline (US Federal)i
March 17, 2022(overdue)
Required action (CISA)i

Apply updates per vendor instructions.

CISA descriptioni

A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 17 marca 2022
Tags
DoSVPN
CWE
References

Related vulnerabilities

CVE-2020-3161CRITICAL9.8⚠ KEVPL ✓same product

RCE i DoS w serwerze HTTP telefonów Cisco IP Phone

CVE-2018-0171CRITICAL9.8⚠ KEVPL ✓same product

RCE i DoS w funkcji Smart Install systemu Cisco IOS przez przepełnienie bufora

CVE-2017-12240CRITICAL9.8⚠ KEVPL ✓same product

Buffer overflow w DHCP relay Cisco IOS — RCE bez uwierzytelnienia

CVE-2017-3881CRITICAL9.8⚠ KEVPL ✓same product

RCE w Cisco IOS/IOS XE – podatność protokołu CMP przez Telnet

CVE-2025-20363CRITICAL9.0PL ✓same product

RCE w web services Cisco ASA, FTD, IOS, IOS XE, IOS XR przez HTTP