EXPOSURES › CVE-2018-0167
CVE-2018-0167
HIGH ⌖ ON CISA KEV · EXPLOITEDAn unauthenticated adjacent attacker could exploit a buffer overflow in Cisco IOS XR LLDP to execute arbitrary code or cause a DoS.
Cisco IOS, XR, and XE Software contained a buffer overflow in the LLDP subsystem allowing remote code execution without authentication. DIB organizations must ensure continuous patching of network infrastructure, as this vulnerability was actively exploited in the wild and represents a systemic failure in input validation across critical networking hardware.
Shame score — A foundational networking vendor shipped a critical RCE vulnerability in an unauthenticated subsystem that was actively exploited in the wild, demonstrating severe negligence in patching and input validation.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software which could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code.
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |