EXPOSURES › CVE-2018-0155
CVE-2018-0155
HIGH ⌖ ON CISA KEV · EXPLOITEDAn unauthenticated remote attacker could crash the iosd process on Cisco Catalyst 4500 switches, causing a denial-of-service condition.
This DoS vulnerability in the BFD offload implementation allowed remote attackers to crash critical network processes without authentication. DIB organizations must patch this unpatched, actively exploited CVE immediately to prevent network outages and maintain compliance with NIST 800-171 requirements for mitigating known vulnerabilities.
Shame score — A known, actively exploited vulnerability in widely deployed network hardware that caused service disruption without requiring authentication.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial-of-service (DoS) condition.
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |