CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2018-0167

Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

Vendor: Cisco

Product: IOS, XR, and XE Software

Added: 2022-03-03

Due Date: 2022-03-17

Description:

There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software which could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2018-0161

Cisco IOS Software Resource Management Errors Vulnerability

Vendor: Cisco

Product: IOS Software

Added: 2022-03-03

Due Date: 2022-03-17

Description:

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial-of-service (DoS) condition.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-399

CVE-2018-0159

Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability

Vendor: Cisco

Product: IOS Software and Cisco IOS XE Software

Added: 2022-03-03

Due Date: 2022-03-17

Description:

A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2018-0158

Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability

Vendor: Cisco

Product: IOS Software and Cisco IOS XE Software

Added: 2022-03-03

Due Date: 2022-03-17

Description:

A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2018-0156

Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability

Vendor: Cisco

Product: IOS Software and Cisco IOS XE Software

Added: 2022-03-03

Due Date: 2022-03-17

Description:

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial-of-service (DoS) condition.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-399

CVE-2018-0155

Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability

Vendor: Cisco

Product: Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches

Added: 2022-03-03

Due Date: 2022-03-17

Description:

A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial-of-service (DoS) condition.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-388

CVE-2018-0154

Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability

Vendor: Cisco

Product: IOS Software

Added: 2022-03-03

Due Date: 2022-03-17

Description:

A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-399

CVE-2018-0151

Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability

Vendor: Cisco

Product: IOS and IOS XE Software

Added: 2022-03-03

Due Date: 2022-03-17

Description:

A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2017-8540

Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability

Vendor: Microsoft

Product: Malware Protection Engine

Added: 2022-03-03

Due Date: 2022-03-24

Description:

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2017-6744

Cisco IOS Software SNMP Remote Code Execution Vulnerability

Vendor: Cisco

Product: IOS software

Added: 2022-03-03

Due Date: 2022-03-24

Description:

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 1 contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2017-6743

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

Vendor: Cisco

Product: IOS and IOS XE Software

Added: 2022-03-03

Due Date: 2022-03-24

Description:

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2017-6740

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

Vendor: Cisco

Product: IOS and IOS XE Software

Added: 2022-03-03

Due Date: 2022-03-24

Description:

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2017-6739

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

Vendor: Cisco

Product: IOS and IOS XE Software

Added: 2022-03-03

Due Date: 2022-03-24

Description:

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2017-6738

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

Vendor: Cisco

Product: IOS and IOS XE Software

Added: 2022-03-03

Due Date: 2022-03-24

Description:

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2017-6737

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

Vendor: Cisco

Product: IOS and IOS XE Software

Added: 2022-03-03

Due Date: 2022-03-24

Description:

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119