LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-0154: Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 17, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-0154 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 17, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial-of-service…

CVE-2018-0154 is a denial-of-service vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) when it runs Cisco IOS Software. An unauthenticated remote attacker could trigger a DoS condition on affected devices. For teams that rely on Cisco IOS for VPN services, this matters because a successful attack can disrupt encrypted traffic handling and availability of the module without needing credentials.

Public detail is limited to the vendor and CISA descriptions; confirm exact platform support, fixed releases, and any configuration prerequisites directly against the Cisco advisory before acting.

How it works

The weakness is categorized as CWE-399 (resource management errors). In this class of flaw, improper handling of resources inside a component—here the crypto engine of the ISM-VPN—can be driven into a state where the module stops functioning correctly.

According to the CISA summary, an unauthenticated remote attacker can interact with the vulnerable crypto engine in a way that produces a denial-of-service condition. No further exploit mechanics, packet formats, or preconditions are provided in the given facts, so defenders should treat any unauthenticated reachability to the ISM-VPN crypto services as the exposure surface and verify the precise trigger conditions in the vendor advisory.

Am I affected? How to find it in your systems

The vulnerability affects Cisco IOS Software running on the Integrated Services Module for VPN (ISM-VPN). These modules are typically installed in Cisco routers or related platforms that provide hardware-assisted VPN and crypto offload.

How to remediate

The required action is to apply updates per vendor instructions. Obtain the fixed Cisco IOS Software release that addresses CVE-2018-0154 from the official advisory and schedule installation according to your change process.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

If your data may have been exposed

This vulnerability is described as a denial-of-service issue; known ransomware use is not documented. Actively exploited vulnerabilities can still lead to broader incidents if attackers use the outage as cover or pivot after gaining other access. If you suspect compromise or have evidence of successful exploitation, follow your incident-response process, preserve logs, and assess whether any credentials or configuration data could have been affected. You can run a free exposure scan of your email addresses against known breach data sets to check for unrelated credential exposures that might increase risk during the window of vulnerability.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · IOS Software
WeaknessCWE-399
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 17, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities