EXPOSURES › CVE-2018-0159
CVE-2018-0159
HIGH ⌖ ON CISA KEV · EXPLOITEDAn unauthenticated remote attacker could force a Cisco IOS/XE device to reload via an IKEv1 DoS vulnerability, causing service disruption.
This CVE allows an unauthenticated remote attacker to trigger a device reload, resulting in a denial-of-service condition. DIB organizations must ensure all Cisco networking equipment is patched to prevent service outages and maintain compliance with NIST 800-171 requirements for mitigating known vulnerabilities. Failure to patch leaves critical infrastructure exposed to exploitation in the wild.
Shame score — A known, actively exploited vulnerability in foundational networking software that causes service disruption without requiring authentication, indicating systemic patching failures.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition.
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |