← Back to browse · API

CVE-2018-0172

Severity
HIGH
CVSS
8.6
EPSS
0.07871
Risk score
62.15
CISA KEV
Yes
PoC
No
Published
2018-03-28
Modified
2026-01-12
First seen
2026-08-07
Aliases
EUVD-2018-0995, GHSA-7F45-F5VF-RRPW
Products
Cisco:IOS and IOS XE Software, n/a:Cisco IOS and IOS XE Cisco IOS and IOS XE
Sources
cisa.gov CVE-2018-0172
euvd EUVD-2018-0995

Description

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software performs incomplete input validation of option 82 information that it receives in DHCP Version 4 (DHCPv4) packets from DHCP relay agents. An attacker could exploit this vulnerability by sending a crafted DHCPv4 packet to an affected device. A successful exploit could allow the attacker to cause a heap overflow condition on the affected device, which will cause the device to reload and result in a DoS condition. Cisco Bug IDs: CSCvg62730.

References