CVE-2018-0154

Published Mar 28, 2018

Last updated 3 days ago

Overview

Description
A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient handling of VPN traffic by the affected device. An attacker could exploit this vulnerability by sending crafted VPN traffic to an affected device. A successful exploit could allow the attacker to cause the affected device to hang or crash, resulting in a DoS condition. Cisco Bug IDs: CSCvd39267.
Source
ykramarz@cisco.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity
HIGH

CVSS 2.0

Type
Primary
Base score
7.8
Impact score
6.9
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:N/I:N/A:C

Known exploits

Data from CISA

Vulnerability name
Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability
Exploit added on
Mar 3, 2022
Exploit action due
Mar 17, 2022
Required action
Apply updates per vendor instructions.

Weaknesses

ykramarz@cisco.com
CWE-399
nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending

Configurations