Buffer overflow in Cisco IOS XE - CVE-2018-0167
Published: March 30, 2018 / Updated: March 8, 2022
Vulnerability details
The vulnerability allows an adjacent unauthenticated attacker to cause DoS condition or execute arbitrary code with elevated privileges on the target system.
The weakness exists in the LLDP subsystem due to improper error handling of malformed LLDP messages. An adjacent attacker can submit a specially crafted LLDP protocol data unit (PDU), trigger buffer overflow, cause the service to crash or execute arbitrary code with root privileges.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
Allen-Bradley Stratix 5900 Services Router
Allen-Bradley Stratix 8300 Modular Managed Ethernet Switches
Allen-Bradley Stratix 5400 Industrial Ethernet Switches
Allen-Bradley Stratix 5410 Industrial Distribution Switches
Allen-Bradley Stratix 5700 Industrial Managed Ethernet Switches
Allen-Bradley ArmorStratix 5700 Industrial Managed Ethernet Switches
Allen-Bradley Stratix 8000 Modular Managed Ethernet Switches
How to mitigate CVE-2018-0167
External References
Related Security Bulletins
- Multiple vulnerabilities in Cisco IOS XE
- Multiple vulnerabilities in Rockwell Automation Allen-Bradley Stratix 5900 Services Router
- Multiple vulnerabilities in Rockwell Automation Stratix and ArmorStratix Switches
- Multiple vulnerabilities in Rockwell Automation Allen-Bradley Stratix 8300 Industrial Managed Ethernet Switches