← Back

CVE-2018-0174

nvd nist
Published: Mar 28, 2018Modified: Jan 14, 2026CISA KEV

JSON object

Loading...
8.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 4.0
Source: NVD

Description

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software performs incomplete input validation of option 82 information that it receives in DHCP Version 4 (DHCPv4) packets from DHCP relay agents. An attacker could exploit this vulnerability by sending a crafted DHCPv4 packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCuh91645.

Affected (6)

Products: Cisco: Ios, Ios Xe
2 products
Ios
Ios Xe
Configuration A
2 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
Version 12.2(33)sre7a
Version 12.2(33)sre7a
Running on/withPlatform Versions
Cisco
7600 Series Route Switch Processor 720
All versions
Cisco
7600 Series Supervisor Engine 32
All versions
Cisco
7600 Series Supervisor Engine 720
All versions
Configuration B
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 15.2\(4a\)ea5
Up to 15.2\(4a\)ea5
Running on/withPlatform Versions
Rockwellautomation
Allen Bradley Stratix 8300
All versions
Configuration C
2 vulnerable · 5 platform
Vulnerable SoftwareAffected Versions
Up to 15.2\(6\)e0a
Up to 15.2\(6\)e0a
Running on/withPlatform Versions
Rockwellautomation
Allen Bradley Armorstratix 5700
All versions
Rockwellautomation
Allen Bradley Stratix 5400
All versions
Rockwellautomation
Allen Bradley Stratix 5410
All versions
Rockwellautomation
Allen Bradley Stratix 5700
All versions
Rockwellautomation
Allen Bradley Stratix 8000
All versions

References (13)

Source: psirt@cisco.com
Broken LinkThird Party AdvisoryVDB Entry
Source: psirt@cisco.com
Broken LinkThird Party AdvisoryVDB Entry
Source: psirt@cisco.com
Third Party AdvisoryUS Government Resource
Source: psirt@cisco.com
Third Party AdvisoryUS Government Resource
Source: psirt@cisco.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.