TROYANOSYVIRUS
Volver a CVEs

CVE-2018-0175

HIGHCISA KEV
8.0

Descripcion

Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCvd73664.

Detalles CVE

Puntuacion CVSS v3.18.0
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vector de ataqueADJACENT_NETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioREQUIRED
Publicado3/28/2018
Ultima modificacion1/14/2026
Fuentekev
Avistamientos honeypot0

CISA KEV

VendedorCisco
ProductoIOS, XR, and XE Software
Nombre vulnerabilidadCisco IOS, XR, and XE Software Buffer Overflow Vulnerability
Fecha inclusion KEV2022-03-03
Fecha limite remediacion2022-03-17
Uso en ransomwareUnknown

Productos afectados

cisco:ioscisco:ios_xecisco:ios_xrrockwellautomation:allen-bradley_armorstratix_5700rockwellautomation:allen-bradley_stratix_5400rockwellautomation:allen-bradley_stratix_5410rockwellautomation:allen-bradley_stratix_5700rockwellautomation:allen-bradley_stratix_5900_services_routerrockwellautomation:allen-bradley_stratix_8000rockwellautomation:allen-bradley_stratix_8300_industrial_managed_ethernet_switch

Debilidades (CWE)

CWE-119CWE-134

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.