EXPOSURES › CVE-2018-0171
CVE-2018-0171
HIGH ⌖ ON CISA KEV · EXPLOITEDCisco IOS and IOS XE Smart Install allows unauthenticated remote attackers to execute code, causing device reloads, DoS, or full compromise.
Cisco IOS and IOS XE improperly validates packet data in the Smart Install feature, enabling unauthenticated remote code execution, denial-of-service, or device reloads. DIB organizations must treat this as a critical supply-chain and infrastructure risk, as compromised network devices can be used as pivots for lateral movement or data exfiltration. Immediate patching and strict network segmentation are required to mitigate exploitation.
Shame score — A foundational networking OS with persistent RCE flaws that are actively exploited in the wild, indicating systemic negligence in input validation and patching.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a denial-of-service (DoS) condition, or perform code execution on the affected device.
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |