← Back to CVE List
Vulnerability Intelligence Report
Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability

CVE-2018-0158

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain IKEv2 packets. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device to be processed. A successful exploit could cause an affected device to continuously consume memory and eventually reload, resulting in a DoS condition. Cisco Bug IDs: CSCvf22394.

CISA KEV SSVC: Active Exploitation Automatable
CVSS Base Score
8.6
HIGH
Exploitability:3.9
Impact Score:4.0
EPSS Probability:7.19%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

Affected Products & Versions

Vendor Product Affected Versions
cisco ios 15.5\(3\)s1.1, 15.5\(3\)s1.2, 15.5\(3\)s1.4, 15.5\(3\)s1.5, 15.5\(3\)s1.7, 15.5\(3\)s1.8, 15.5\(3\)s1.9, 15.5\(3\)s1.10, 15.5\(3\)s1.11, 15.5\(3\)s1.12
cisco asr_1001-hx all
cisco asr_1001-x all
cisco asr_1002-hx all
cisco asr_1002-x all
cisco asr_1004 all
cisco asr_1006 all
cisco asr_1006-x all
cisco asr_1009-x all
cisco asr_1013 all
cisco ios_xe 15.5\(3\)s1.1, 15.5\(3\)s1.2, 15.5\(3\)s1.4, 15.5\(3\)s1.5, 15.5\(3\)s1.7, 15.5\(3\)s1.8, 15.5\(3\)s1.9, 15.5\(3\)s1.10, 15.5\(3\)s1.11, 15.5\(3\)s1.12
rockwellautomation allen-bradley_stratix_5900 all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
7.194%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCisco Systems, Inc. · Hosted Service · USA
Reserved2017-11-27T00:00:00
Published2018-03-28T22:00:00
Patch Date2018-03-28
Last Updated2026-01-12T21:54:43

LINK COPIED TO CLIPBOARD