HIGH · 8.6

CVE-2018-0158

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload...

Vulnerability Description

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain IKEv2 packets. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device to be processed. A successful exploit could cause an affected device to continuously consume memory and eventually reload, resulting in a DoS condition. Cisco Bug IDs: CSCvf22394.

CVSS Score

8.6

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
CiscoIos15.5\(3\)s1.1
CiscoAsr 1001-Hx-
CiscoAsr 1001-X-
CiscoAsr 1002-Hx-
CiscoAsr 1002-X-
CiscoAsr 1004-
CiscoAsr 1006-
CiscoAsr 1006-X-
CiscoAsr 1009-X-
CiscoAsr 1013-
CiscoIos Xe15.5\(3\)s1.1
RockwellautomationAllen-Bradley Stratix 5900-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-0158?

CVE-2018-0158 is a vulnerability with a CVSS score of 8.6 (HIGH). A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload...

How severe is CVE-2018-0158?

CVE-2018-0158 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-0158?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios, Cisco Asr 1001-Hx, Cisco Asr 1001-X, Cisco Asr 1002-Hx, Cisco Asr 1002-X.