EXPOSURES › CVE-2018-0156
CVE-2018-0156
HIGH ⌖ ON CISA KEV · EXPLOITEDAn unauthenticated remote attacker could force a Cisco IOS device to reload, causing a denial-of-service via the Smart Install feature.
This DoS vulnerability allows an unauthenticated remote attacker to trigger a device reload, disrupting network operations and violating availability requirements. DIB organizations must ensure continuous patching of network infrastructure to prevent such disruptions and maintain compliance with NIST 800-171 controls on system integrity and availability.
Shame score — A known vulnerability in a foundational networking product that was actively exploited in the wild, indicating systemic issues in patching and input validation.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial-of-service (DoS) condition.
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |