EXPOSURES › CVE-2018-0151
CVE-2018-0151
HIGH ⌖ ON CISA KEV · EXPLOITEDAn unauthenticated remote attacker could execute arbitrary code with elevated privileges in Cisco IOS and IOS XE QoS subsystems.
Cisco IOS and IOS XE software contained a remote code execution vulnerability in the QoS subsystem allowing unauthenticated attackers to execute arbitrary code with elevated privileges. This failure is critical for DIB organizations because it enables full system compromise, violates CMMC/NIST 800-171 requirements for protecting unclassified information, and highlights systemic issues in Cisco's historical patching of high-severity RCE flaws. Organizations must ensure all network infrastructure is patched to the latest versions and restrict access to network devices to prevent exploitation.
Shame score — A high-severity remote code execution vulnerability in foundational networking software that was actively exploited in the wild, reflecting systemic neglect of critical security flaws in widely deployed infrastructure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges.
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |