Resource management errors in Cisco IOS XE - CVE-2018-0179

 

Resource management errors in Cisco IOS XE - CVE-2018-0179

Published: March 29, 2018 / Updated: March 8, 2022


Vulnerability identifier: #VU11338
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0179
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.

The weakness exists due to an attempt to free an area of memory that has not been previously allocated. A remote attacker can attempt to log in via Secure Shell (SSH) or Telnet with invalid credentials multiple times and cause the service to crash.

Affected software

Cisco IOS XE

How to mitigate CVE-2018-0179

Update to versions 15.7(3.1.8A)OT, 15.7(3.1.4A)OT, 15.6(3)M, 15.6(2.12.1a)T0, 15.6(2.3)T, 15.6(2)T0.1, 15.5(3)M2.1, 15.4(3)M6 or 15.4(1)IA1.102.


External References

Related Security Bulletins