← All CVEs

CVE-2018-0175

high · 8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-03-03Remediation due 2022-03-17

Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCvd73664.

8
CVSS
3.5%
EPSS (exploit prob.)
89th
EPSS percentile
2018-03-28
Published

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-119CWE-134

Affected products

VendorProductAffected versions
ciscoios15.4(3)m4.1
ciscoios_xe15.4(3)m4.1
ciscoios_xr15.4(3)m4.1
ciscoios<= 15.2\(4a\)ea5
ciscoios_xe<= 15.2\(4a\)ea5
rockwellautomationallen-bradley_stratix_8300_industrial_managed_ethernet_switchall versions
ciscoios<= 15.2\(6\)e0a
ciscoios_xe<= 15.2\(6\)e0a
rockwellautomationallen-bradley_armorstratix_5700all versions
rockwellautomationallen-bradley_stratix_5400all versions
rockwellautomationallen-bradley_stratix_5410all versions
rockwellautomationallen-bradley_stratix_5700all versions
rockwellautomationallen-bradley_stratix_8000all versions
ciscoios<= 15.6.3m1
ciscoios_xe<= 15.6.3m1
rockwellautomationallen-bradley_stratix_5900_services_routerall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-0175