LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-0175: Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 17, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-0175 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 17, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent…

CVE-2018-0175 is a vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software. It can let an unauthenticated attacker on an adjacent network segment cause a denial of service or run code with elevated privileges on a vulnerable device. Network infrastructure that speaks LLDP is a high-value target; a successful attack can disrupt connectivity or give an adversary a foothold on core routing and switching gear.

Public detail is limited to the vendor and CISA descriptions. Confirm exact affected releases, fixed versions, and any configuration prerequisites directly against Cisco’s advisory before acting.

How it works

The weakness is classified as CWE-119 (improper restriction of operations within the bounds of a memory buffer). CISA describes it as a format-string issue in the LLDP subsystem. LLDP is a Layer-2 neighbor-discovery protocol commonly enabled on switch and router interfaces so devices can exchange identity and capability information.

An unauthenticated, adjacent attacker who can send crafted LLDP frames to a vulnerable interface may trigger the flaw. Depending on how the malformed input is processed, the result can be a crash (denial of service) or arbitrary code execution with elevated privileges on the device. No remote, unauthenticated attack over Layer 3 is indicated; the attacker must be able to reach the device at Layer 2 on a segment where LLDP is processed. Specific exploit mechanics and packet formats are not provided in the given facts and must not be assumed; refer to the vendor advisory for any additional technical detail.

Am I affected? How to find it in your systems

The vulnerability affects Cisco IOS, IOS XE, and IOS XR Software that include the LLDP subsystem. These images typically run on enterprise and service-provider routers, switches, and related network devices.

Because version ranges and platform applicability are not listed in the facts supplied here, treat every IOS/XE/XR device as potentially in scope until you have verified it against the official advisory.

How to remediate

The required action is to apply the updates Cisco released for this vulnerability, following the vendor’s installation and verification instructions. Patching is the primary and definitive fix.

No alternative permanent fix is described in the given facts; configuration hardening alone does not replace the vendor update.

If you can't patch immediately

Until the fixed software can be deployed, reduce exposure with compensating controls appropriate to an adjacent, unauthenticated LLDP flaw:

These steps lower risk but do not eliminate it; schedule the vendor update as soon as practicable.

If your data may have been exposed

Actively exploited vulnerabilities on network devices can lead to broader compromise, including traffic interception or lateral movement. Known ransomware use of this CVE is not documented in the supplied facts. If you suspect a device was targeted, isolate it, preserve logs and memory if feasible, and follow your incident-response process. As a routine hygiene step, you can run a free exposure scan of your email addresses against known breach data sets to see whether credentials or personal information have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · IOS, XR, and XE Software
WeaknessCWE-119
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 17, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities