EXPOSURES › CVE-2018-0172
CVE-2018-0172
HIGH ⌖ ON CISA KEV · EXPLOITEDCisco IOS and IOS XE Software suffered a DoS vulnerability in DHCP option 82 encapsulation that was actively exploited in the wild.
The vulnerability allowed denial-of-service attacks via improper input validation in the DHCP option 82 encapsulation functionality. DIB organizations must ensure continuous patching of network infrastructure, as Cisco has a history of high-severity RCE vulnerabilities in subsystems like SNMP and DHCP. Failure to patch exposes networks to service disruption and potential lateral movement.
Shame score — The vulnerability was actively exploited in the wild (KEV) and linked to systemic input validation issues in foundational networking software, indicating avoidable negligence in patching and design.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |