LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-0158: Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 17, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-0158 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 17, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause…

CVE-2018-0158 is a denial-of-service vulnerability in the Internet Key Exchange Version 1 (IKEv1) implementation in Cisco IOS Software and Cisco IOS XE Software. An unauthenticated remote attacker can trigger it to force an affected device to reload, disrupting network availability.

For IT and security teams running Cisco routers or switches that terminate IPsec or related VPN traffic, this matters because a simple remote condition can take critical infrastructure offline until it recovers. Confirm all version and configuration details against the vendor advisory before acting.

How it works

The underlying weakness is classified as CWE-20 (Improper Input Validation). In this case it manifests as a memory leak within the IKEv1 handling code of Cisco IOS and IOS XE.

An attacker who can reach the IKEv1 service on an affected device sends crafted packets that the software fails to process cleanly. Over time the leak exhausts resources until the device reloads, producing a denial-of-service condition. No authentication is required. Exact packet formats and trigger conditions are not detailed here; treat any publicly reachable IKEv1 endpoint as potentially exposed and verify behavior against the Cisco advisory.

Am I affected? How to find it in your systems

Cisco IOS and IOS XE commonly run on enterprise and service-provider routers, switches, and security appliances that terminate site-to-site or remote-access VPNs. Inventory every device that has IKEv1 enabled or that listens on the standard IKE ports.

How to remediate

Patch first. Apply the Cisco software updates identified in the vendor advisory for CVE-2018-0158, following Cisco’s published installation and verification procedures. CISA’s required action is simply to apply updates per vendor instructions.

After patching, harden the IKEv1 attack surface:

If you can't patch immediately

Reduce exposure until the vendor update can be installed:

If your data may have been exposed

This vulnerability produces a denial-of-service condition rather than direct data exfiltration, and ransomware use is not documented. Nevertheless, any actively exploited remote flaw can be a stepping-stone in a larger intrusion. If you suspect compromise, follow your incident-response process, preserve logs, and examine adjacent systems. You can also run a free exposure scan of your email addresses against known breach data sets to check whether credentials or personal information have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · IOS Software and Cisco IOS XE Software
WeaknessCWE-20
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 17, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities