Skip to content
COOEY

EXPOSURES › CVE-2018-0175

CVE-2018-0175

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-0175 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

A format string vulnerability in Cisco IOS XR/IOS XE LLDP allowed unauthenticated adjacent attackers to execute arbitrary code with elevated privileges.

Cisco IOS, XR, and XE Software contained a format string vulnerability in the LLDP subsystem that permitted unauthenticated adjacent attackers to execute arbitrary code with elevated privileges or cause a DoS. DIB organizations must ensure continuous patching of network infrastructure, as this vulnerability was actively exploited in the wild and represents a systemic failure in input validation across critical networking equipment.

Shame score — A format string vulnerability in a foundational networking OS allowed unauthenticated adjacent attackers to execute arbitrary code with elevated privileges, indicating severe input validation failures in a widely deployed product.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device.

AFFECTED FEDRAMP PRODUCTS · 9
PRODUCTSTATUS
AppDynamics GovAPM
AppDynamics (a Cisco company)
Authorized
Cisco Cloudlock for Government
Cisco Systems Inc.
Authorized
Cisco Meraki for Government
Cisco Systems Inc.
In Process
Cisco SD-WAN for Government
Cisco Systems Inc.
In Process
Cisco Umbrella for Government
Cisco Systems Inc.
In Process
Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
Cisco Systems Inc.
Authorized
Duo Federal
Duo Security (A Cisco Company)
Authorized
WebEx Contact Center Enterprise for Government (WxCCE-G)
Cisco Systems Inc.
In Process
Webex for Government
Cisco Systems Inc.
Authorized