← Back to browse · API

CVE-2018-0158

Severity
HIGH
CVSS
8.6
EPSS
0.07237
Risk score
61.93
CISA KEV
Yes
PoC
No
Published
2018-03-28
Modified
2026-01-12
First seen
2026-08-07
Aliases
EUVD-2018-0981, GHSA-FM8F-3J2C-52XR
Products
Cisco:IOS Software and Cisco IOS XE Software, n/a:Cisco IOS and IOS XE Cisco IOS and IOS XE
Sources
cisa.gov CVE-2018-0158
euvd EUVD-2018-0981

Description

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain IKEv2 packets. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device to be processed. A successful exploit could cause an affected device to continuously consume memory and eventually reload, resulting in a DoS condition. Cisco Bug IDs: CSCvf22394.

References