LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-0179: Cisco IOS Software Denial-of-Service Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 17, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-0179 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 17, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial…

CVE-2018-0179 is a denial-of-service vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software. An unauthenticated remote attacker can trigger a reload of an affected device, interrupting network services that depend on it. For IT and security teams, this matters because Cisco IOS commonly runs on core routing and switching infrastructure; a forced reload can disrupt connectivity, management access, and dependent business functions until the device recovers.

Public detail is limited to the CISA description and the associated weakness class. Confirm exact affected releases, fixed software, and configuration prerequisites against the vendor advisory before prioritizing work.

How it works

The weakness is tracked as CWE-399 (resource management errors). In this case, the flaw sits in the Login Enhancements (Login Block) feature of Cisco IOS Software. When that feature is present and reachable, an unauthenticated remote attacker can interact with it in a way that causes the device to reload, producing a denial-of-service condition.

At a high level, resource-management flaws of this class allow an attacker to exhaust, corrupt, or otherwise mishandle internal state so that the system can no longer continue normal operation and restarts. The CISA summary does not describe packet formats, exact trigger sequences, or preconditions beyond the Login Block feature and unauthenticated remote access. Do not assume exploit mechanics; treat any public proof-of-concept claims with caution and validate behavior only in a controlled lab against vendor guidance.

Am I affected? How to find it in your systems

Cisco IOS Software typically runs on enterprise and service-provider routers, switches, and related network appliances. Inventory every device that reports a Cisco IOS image: management platforms, configuration backups, CDP/LLDP neighbor data, and authentication or TACACS/RADIUS logs are practical starting points.

If inventory tooling cannot confirm the feature state, treat the device as potentially affected until the advisory checklist is completed.

How to remediate

Patch first. Apply the Cisco software updates specified for CVE-2018-0179 exactly as directed in the vendor advisory. CISA’s required action is to apply updates per vendor instructions; schedule maintenance windows that account for reload and adjacency reconvergence.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls appropriate to a remote DoS against the login feature.

These steps lower risk; they do not replace the patch.

If your data may have been exposed

This vulnerability is described as a denial-of-service condition leading to device reload. Public information does not document ransomware use or direct data exfiltration via this CVE. A successful attack could still coincide with broader intrusion activity if attackers used the outage as cover or already had other access. If you suspect compromise, preserve crashinfo and logs, rebuild or reload from known-good images if integrity is in doubt, and rotate credentials that may have traversed the affected devices. You can run a free exposure scan of your email addresses against known breach data sets to check whether accounts tied to your environment appear in unrelated breaches while you complete incident review.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · IOS Software
WeaknessCWE-399
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 17, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities