LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-0174: Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 17, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-0174 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 17, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).

CVE-2018-0174 is an improper input validation flaw in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software. A remote attacker who can send crafted DHCP traffic could trigger a denial-of-service condition on a vulnerable device, disrupting network availability for users and services that depend on that router or switch.

For IT and security teams, this matters because Cisco IOS and IOS XE platforms commonly sit at the core or edge of enterprise and campus networks. An unpatched device can become a single point of failure if the DHCP-related path is reachable. Confirm exact affected releases and fixed code against the vendor advisory before acting.

How it works

The weakness is classified as CWE-20 (Improper Input Validation). In this case, the vulnerable code path handles DHCP option 82 encapsulation. Option 82 is used by relays and access devices to insert circuit and remote-ID information into DHCP messages so that servers can make policy or addressing decisions.

When input validation is insufficient, specially crafted DHCP messages that exercise the option 82 encapsulation logic can cause the device to fail in a way that produces a denial-of-service condition. Public detail does not describe memory corruption leading to code execution or other impact beyond DoS; treat the primary risk as availability loss on the affected Cisco IOS or IOS XE system. Specific packet formats and trigger conditions must be confirmed against the vendor advisory rather than assumed from general DHCP knowledge.

Am I affected? How to find it in your systems

Cisco IOS and IOS XE run on a wide range of enterprise routers, switches, and related network platforms. Inventory every device that could process or relay DHCP traffic, especially those configured for DHCP relay, snooping, or option 82 insertion.

If you cannot map a device to a clear fixed release, treat it as potentially affected until the vendor matrix says otherwise.

How to remediate

Patching is the primary remediation. Apply the Cisco software updates identified in the vendor advisory for CVE-2018-0174, following Cisco’s published upgrade paths and release notes for your hardware platform.

CISA’s required action is to apply updates per vendor instructions. Track completion in your vulnerability management system and retain evidence of the installed fixed release.

If you can't patch immediately

Until you can install the vendor fix, reduce exposure with compensating controls focused on the DHCP option 82 attack surface and device reachability.

These steps lower likelihood and impact of a DoS attempt but do not replace the vendor update.

If your data may have been exposed

Public information on CVE-2018-0174 describes a denial-of-service impact, and ransomware use is not documented for this CVE. A successful DoS does not by itself imply data exfiltration; however, any period of device instability or recovery can coincide with broader intrusion activity. If you have evidence of compromise on adjacent systems, follow your incident response process, preserve logs, and rotate credentials where appropriate. You can also run a free exposure scan of your email addresses against known breach datasets to see whether your identities appear in unrelated historical breaches while you complete network remediation.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · IOS XE Software
WeaknessCWE-20
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 17, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities