EXPOSURES › CVE-2018-0175
CVE-2018-0175
HIGH ⌖ ON CISA KEV · EXPLOITEDA format string vulnerability in Cisco IOS XR/IOS XE LLDP allowed unauthenticated adjacent attackers to execute arbitrary code with elevated privileges.
Cisco IOS, XR, and XE Software contained a format string vulnerability in the LLDP subsystem that permitted unauthenticated adjacent attackers to execute arbitrary code with elevated privileges or cause a DoS. DIB organizations must ensure continuous patching of network infrastructure, as this vulnerability was actively exploited in the wild and represents a systemic failure in input validation across critical networking equipment.
Shame score — A format string vulnerability in a foundational networking OS allowed unauthenticated adjacent attackers to execute arbitrary code with elevated privileges, indicating severe input validation failures in a widely deployed product.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device.
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |