LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-0155: Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 17, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-0155 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 17, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated…

CVE-2018-0155 is a denial-of-service vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation on Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches. An unauthenticated remote attacker can trigger a crash of the iosd process, disrupting switch operation. For network teams this matters because these platforms often sit in core or distribution roles; a successful attack can interrupt forwarding and management until the device recovers.

Public detail is limited to the CISA description and the stated weakness class. Confirm exact exposure, fixed software, and any configuration prerequisites against the vendor advisory before acting.

How it works

The weakness is categorized as CWE-388 (error handling). In this case the flaw resides in how the switch’s BFD offload path processes certain traffic. BFD is a lightweight protocol used to detect forwarding-path failures quickly; when offloaded to hardware or specialized code paths, malformed or unexpected BFD-related packets can reach that path.

An unauthenticated remote attacker who can send traffic that reaches the vulnerable BFD offload implementation may cause the iosd process to crash. Loss of iosd produces a denial-of-service condition on the switch. No further exploit mechanics, packet formats, or preconditions are supplied in the available facts; treat any public proof-of-concept claims cautiously and validate them only against official vendor information.

Am I affected? How to find it in your systems

The vulnerability affects Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches that implement BFD offload. These devices commonly appear in campus distribution, collapsed-core, and data-center edge roles.

How to remediate

Patch first. Apply the software updates specified by Cisco for the affected Catalyst 4500 and 4500-X platforms, following the vendor’s installation and verification instructions. CISA’s required action is simply to apply updates per vendor instructions.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

If your data may have been exposed

This vulnerability is a denial-of-service condition; the supplied facts do not document data exfiltration or ransomware use. Nevertheless, any actively exploited network-device vulnerability can be a stepping stone to broader compromise. If you observe crashes or suspicious traffic consistent with exploitation, treat the incident as a potential intrusion: isolate affected devices, preserve logs and crashinfo, and follow your incident-response process. As a routine hygiene step, you can run a free exposure scan of your email addresses against known breach data sets to check whether credentials or other information have appeared in prior breaches unrelated to this CVE.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches
WeaknessCWE-388
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 17, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities