← Back

CVE-2018-0158

nvd nist
Published: Mar 28, 2018Modified: Jan 14, 2026CISA KEV

JSON object

Loading...
8.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 4.0
Source: NVD

Description

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain IKEv2 packets. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device to be processed. A successful exploit could cause an affected device to continuously consume memory and eventually reload, resulting in a DoS condition. Cisco Bug IDs: CSCvf22394.

Affected (20)

Products: Cisco: Ios, Ios Xe
2 products
Ios
Ios Xe
Configuration B
9 platform
Running on/withPlatform Versions
Cisco
Asr 1001 Hx
All versions
Cisco
Asr 1001 X
All versions
Cisco
Asr 1002 Hx
All versions
Cisco
Asr 1002 X
All versions
Cisco
Asr 1004
All versions
Cisco
Asr 1006
All versions
Cisco
Asr 1006 X
All versions
Cisco
Asr 1009 X
All versions
Cisco
Asr 1013
All versions
Configuration C
20 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 15.5(3)s1.10
Version 15.5(3)s1.11
Version 15.5(3)s1.12
Version 15.5(3)s1.1
Version 15.5(3)s1.2
Version 15.5(3)s1.4
Version 15.5(3)s1.5
Version 15.5(3)s1.7
Version 15.5(3)s1.8
Version 15.5(3)s1.9
Cisco
Version 15.5(3)s1.10
Version 15.5(3)s1.11
Version 15.5(3)s1.12
Version 15.5(3)s1.1
Version 15.5(3)s1.2
Version 15.5(3)s1.4
Version 15.5(3)s1.5
Version 15.5(3)s1.7
Version 15.5(3)s1.8
Version 15.5(3)s1.9
Running on/withPlatform Versions
Rockwellautomation
Allen Bradley Stratix 5900
All versions

References (11)

Source: psirt@cisco.com
Broken LinkThird Party AdvisoryVDB Entry
Source: psirt@cisco.com
Broken LinkThird Party AdvisoryVDB Entry
Source: psirt@cisco.com
Third Party AdvisoryUS Government ResourceVDB Entry
Source: psirt@cisco.com
Third Party AdvisoryUS Government ResourceVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government ResourceVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government ResourceVDB Entry
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.