EXPOSURES › CVE-2018-0158
CVE-2018-0158
HIGH ⌖ ON CISA KEV · EXPLOITEDA memory leak in Cisco IOS and XE IKEv1 allowed remote attackers to cause device reboots, resulting in denial-of-service.
An unauthenticated remote attacker could trigger a denial-of-service by causing affected Cisco devices to reload via a memory leak in IKEv1. DIB organizations must ensure continuous patching of network infrastructure, as unpatched vulnerabilities in foundational software like Cisco IOS can lead to service disruptions and compliance gaps. This failure highlights the risk of relying on legacy protocols and the necessity of strict change management and vulnerability scanning.
Shame score — The vulnerability was actively exploited in the wild (KEV) but did not lead to data breaches or ransomware, resulting in a moderate embarrassment score due to the DoS impact and unpatched status.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition.
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |