TROYANOSYVIRUS
Volver a CVEs

CVE-2018-0167

HIGHCISA KEV
8.8

Descripcion

Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCuo17183, CSCvd73487.

Detalles CVE

Puntuacion CVSS v3.18.8
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueADJACENT_NETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado3/28/2018
Ultima modificacion1/14/2026
Fuentekev
Avistamientos honeypot0

CISA KEV

VendedorCisco
ProductoIOS, XR, and XE Software
Nombre vulnerabilidadCisco IOS, XR, and XE Software Buffer Overflow Vulnerability
Fecha inclusion KEV2022-03-03
Fecha limite remediacion2022-03-17
Uso en ransomwareUnknown

Productos afectados

cisco:asr_9001cisco:asr_9006cisco:asr_9010cisco:asr_9904cisco:asr_9906cisco:asr_9910cisco:asr_9912cisco:asr_9922cisco:ioscisco:ios_xecisco:ios_xrrockwellautomation:allen-bradley_armorstratix_5700rockwellautomation:allen-bradley_stratix_5400rockwellautomation:allen-bradley_stratix_5410rockwellautomation:allen-bradley_stratix_5700rockwellautomation:allen-bradley_stratix_5900rockwellautomation:allen-bradley_stratix_8000rockwellautomation:allen-bradley_stratix_8300

Debilidades (CWE)

CWE-119CWE-119

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.