CVE-2018-0175
Cisco IOS, IOS XE, and IOS XR
Published 28 Mar 2018 · updated 17 Jun 2026 · Analyzed
8.0 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Mar 2022, with a remediation deadline of 17 Mar 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCvd73664.
References
- www.securityfocus.com/bid/103564 · Broken Link, Third Party Advisory, VDB Entry
- www.securitytracker.com/id/1040586 · Broken Link, Third Party Advisory, VDB Entry
- ics-cert.us-cert.gov/advisories/ICSA-18-107-03 · Third Party Advisory, US Government Resource
- ics-cert.us-cert.gov/advisories/ICSA-18-107-04 · Third Party Advisory, US Government Resource
- ics-cert.us-cert.gov/advisories/ICSA-18-107-05 · Third Party Advisory, US Government Resource
- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-lldp · Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-0175 · US Government Resource