LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-0172: Cisco IOS and IOS XE Software Improper Input Validation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 17, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-0172 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 17, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).

CVE-2018-0172 is an improper input validation weakness in the DHCP option 82 encapsulation functionality of Cisco IOS and IOS XE Software. A remote attacker who can send crafted DHCP traffic toward an affected device may trigger a denial-of-service condition, disrupting network services that rely on that device. For IT and security teams, this matters because core routing and switching infrastructure often runs these operating systems; an outage can cascade across segments that depend on them.

Public detail is limited to the denial-of-service impact described by CISA. Confirm exact affected releases, fixed software trains, and any configuration prerequisites against the vendor advisory before acting.

How it works

The flaw is classified as CWE-20 (Improper Input Validation). In products that process DHCP option 82 (Relay Agent Information), the software fails to adequately validate certain encapsulated data before handling it. An attacker who can reach the DHCP-related processing path can supply malformed input that the device does not reject cleanly. The result, per the CISA summary, is a denial-of-service condition rather than code execution or data theft.

Technical readers should treat this as a classic parser or encapsulation handling defect: the device accepts traffic it should drop or sanitize, and the failure mode exhausts or crashes the affected process or interface logic. Exact packet structure, required adjacency, and crash signatures are not provided in the given facts; obtain those only from the vendor advisory and lab validation.

Am I affected? How to find it in your systems

Cisco IOS and IOS XE commonly run on enterprise and service-provider routers, switches, and related appliances that perform Layer 2/3 forwarding and DHCP relay. Inventory every device that could be acting as a DHCP relay or otherwise processing option 82.

If your asset inventory is incomplete, prioritize internet-facing or WAN-edge devices and any segment where untrusted DHCP clients or relays exist.

How to remediate

Patch first. CISA’s required action is to apply updates per vendor instructions. Download and install the fixed Cisco IOS or IOS XE software train that addresses CVE-2018-0172, following your standard change window, image verification, and rollback procedures.

Document the advisory ID, pre- and post-patch versions, and any compensating controls left in place.

If you can't patch immediately

Reduce exposure until the vendor update can be applied.

These steps lower likelihood and impact but do not replace the vendor fix.

If your data may have been exposed

This vulnerability is described as a denial-of-service issue; the provided facts do not document ransomware use or direct data exfiltration. Actively exploited infrastructure flaws can still be a foothold for broader incidents, so verify that no secondary compromise occurred during any outage window. Review device logs, authentication records, and downstream systems for anomalies. You can run a free exposure scan of your email addresses against known breach data to check whether credentials or personal information appear in unrelated third-party breaches while you complete containment and patching.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · IOS and IOS XE Software
WeaknessCWE-20
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 17, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities