CVE Tools

Description

A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient handling of VPN traffic by the affected device. An attacker could exploit this vulnerability by sending crafted VPN traffic to an affected device. A successful exploit could allow the attacker to cause the affected device to hang or crash, resulting in a DoS condition. Cisco Bug IDs: CSCvd39267.

In plain language

AI Act now

CVE-2018-0154 is a flaw in Cisco IOS VPN (Cisco ISM-VPN) that can let anyone on the network send special VPN traffic to crash or freeze the device—if you use this VPN, you should act now.

Executive summary

CVE-2018-0154 is an unauthenticated, remote denial-of-service in the Cisco ISM-VPN crypto engine on Cisco IOS; it is triggered by sending crafted VPN traffic that the device fails to handle correctly, causing it to hang or crash.

If affected, business impact
VPN outage for employees and customersRemote access disruptionsService downtime and recovery costsPossible inability to process transactions

What to do now

  1. Check whether your Cisco IOS device is using Cisco ISM-VPN for VPN service and whether your software version matches an affected release referenced by Cisco’s advisory for CVE-2018-0154.
  2. If affected, upgrade to the Cisco IOS version that Cisco’s advisory identifies as fixed for CVE-2018-0154.
  3. After updating, test VPN connectivity and verify the VPN service stays stable under normal usage.
  4. If you cannot patch right away, restrict network access to the VPN endpoint (limit who can reach the VPN from the internet or other networks) and monitor for unusual VPN traffic patterns.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:NI:NA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:NConfidentiality
None
I:NIntegrity
None
A:HAvailability
High

Weaknesses

Affected Products

Cisco Systems Inc.
commercial·USaka cisco, cisco systems
and 2 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Mar 3, 2022
Remediation due:Mar 17, 2022

Required action: Apply updates per vendor instructions.

Official Patch Available

References

and 4 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2018-0154 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows