LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-0173: Cisco IOS and IOS XE Software Improper Input Validation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
CVSS 8.6 · High⚠ Actively exploited (CISA KEV)
8.6
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 17, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-0173 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 17, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a Relay Reply denial of service (DoS) condition. The vulnerability exists because the affected software performs incomplete input validation of encapsulated option 82 information that it receives in DHCPOFFER messages from DHCPv4 servers. An attacker could exploit this vulnerability by sending a crafted DHCPv4 packet to an affected device, which the device would then forward to a DHCPv4 server. When the affected software processes the option 82 information that is encapsulated in the response from the server, an error could occur. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvg62754.

CVE-2018-0173 is an improper input validation weakness in Cisco IOS and IOS XE Software that affects how the platform restores encapsulated DHCP option 82 information in DHCPv4 packets. A crafted packet can trigger a denial-of-service condition on the device. For network teams this matters because IOS and IOS XE commonly sit at the edge and core of enterprise networks; a successful DoS can disrupt routing, switching, and DHCP services that many other systems depend on.

Public detail is limited to the DoS impact described by CISA. Confirm exact affected releases, fixed software trains, and any additional impact statements directly against the vendor advisory before prioritizing work.

How it works

The flaw is classified as CWE-20 (Improper Input Validation). The vulnerable function processes DHCPv4 packets that carry encapsulated option 82 data and attempts to restore that information. When the input is not validated correctly, malformed or unexpected option 82 content can cause the software to fail in a way that results in a denial-of-service condition.

An attacker who can send DHCPv4 traffic to an affected interface—typically from a position that reaches the DHCP relay or server path—can abuse the restoration logic. No further exploit mechanics are provided in the available facts; defenders should treat any untrusted DHCP traffic that reaches the device as a potential trigger and verify the precise packet conditions in the Cisco advisory.

Am I affected? How to find it in your systems

Cisco IOS and IOS XE run on a wide range of routers, switches, and aggregation platforms. Inventory every device that terminates or relays DHCPv4 traffic, especially those configured as DHCP relays or servers that handle option 82.

How to remediate

Patching is the primary remediation. Apply the Cisco software updates identified for CVE-2018-0173 exactly as directed in the vendor advisory. CISA’s required action is simply to apply updates per vendor instructions.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls:

These steps only lower risk; they do not eliminate the vulnerability. Plan the permanent software upgrade as soon as possible.

If your data may have been exposed

The facts describe a denial-of-service impact and do not document ransomware use or direct data exfiltration. Nevertheless, any actively exploited network-device vulnerability can be a stepping stone to broader compromise. If you suspect the device was targeted, examine adjacent systems for follow-on activity and review DHCP and authentication logs for anomalies. You can also run a free exposure scan of your email addresses against known breach data sets to check whether credentials or other information have appeared in prior incidents unrelated to this CVE.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · IOS and IOS XE Software
WeaknessCWE-20
CVSS base score8.6 (High)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
PublishedMar 28, 2018
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 17, 2022
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities