CVE-2018-0171
Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability - [Actively Exploited]
Description
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute arbitrary code on an affected device. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted Smart Install message to an affected device on TCP port 4786. A successful exploit could allow the attacker to cause a buffer overflow on the affected device, which could have the following impacts: Triggering a reload of the device, Allowing the attacker to execute arbitrary code on the device, Causing an indefinite loop on the affected device that triggers a watchdog crash. Cisco Bug IDs: CSCvg76186.
INFO
Published Date :
March 28, 2018, 10:29 p.m.
Last Modified :
Jan. 27, 2025, 7:58 p.m.
Remotely Exploit :
Yes !
Source :
[email protected]
CISA KEV (Known Exploited Vulnerabilities)
For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild.
Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a denial-of-service (DoS) condition, or perform code execution on the affected device.
Apply updates per vendor instructions.
https://nvd.nist.gov/vuln/detail/CVE-2018-0171
CVSS Scores
Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
---|---|---|---|---|---|---|
CVSS 2.0 | HIGH | [email protected] | ||||
CVSS 3.1 | CRITICAL | [email protected] |
Solution
- Upgrade affected Cisco IOS and IOS XE Software to a fixed version.
- Refer to Cisco bug ID(s) CSCvg76186 for specific patched versions.
Public PoC/Exploit Available at Github
CVE-2018-0171 has a 13 public
PoC/Exploit
available at Github.
Go to the Public Exploits
tab to see the list.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2018-0171
.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2018-0171
is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2018-0171
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
None
Cisco SmartInstall Exploit [CVE-2018-0171]
cisco exploit cve-2018-0171 smartinstall
Python
None
Ostorlab KEV: One-command to detect most remotely known exploitable vulnerabilities. Sourced from CISA KEV, Google's Tsunami, Ostorlab's Asteroid and Bug Bounty programs.
cisa-kev vulnerability 0day cisa exploits
Automates searching CVEs in the Metasploit database of exploits.
Python
None
checking alerts of X-CERT
Go
None
Python
For novices
None
Python
A wrapper for Cisco's smi_check.py file.
Python
None
✍️ A curated list of CVE PoCs.
awesome cve poc
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2018-0171
vulnerability anywhere in the article.

-
CybersecurityNews
Weekly Cybersecurity News Recap : Apple 0-day, Chrome, Copilot Vulnerabilities and Cyber Attacks
This past week was packed with high-severity disclosures and active exploitation reports across the global threat landscape. At the forefront, Apple rushed out emergency patches for yet another zero-d ... Read more

-
Help Net Security
Week in review: Covertly connected and insecure Android VPN apps, Apple fixes exploited zero-day
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Android VPN apps used by millions are covertly connected AND insecure Three families of Android VPN ap ... Read more

-
Help Net Security
China-linked Murky Panda targets and moves laterally through cloud services
In its recently released 2025 Threat Hunting Report, Crowdstrike pointed out an interesting trend: a 136% surge in cloud intrusions. A good chunk of this surge is due to “China-nexus adversaries”, Mur ... Read more

-
Help Net Security
AI gives ransomware gangs a deadly upgrade
Ransomware continues to be the major threat to large and medium-sized businesses, with numerous ransomware gangs abusing AI for automation, according to Acronis. Ransomware gangs maintain pressure on ... Read more

-
TheCyberThrone
CVE-2025-43300 affects Apple Products
August 22, 2025Vulnerability SummaryCVE-2025-43300 is a zero-day out-of-bounds write vulnerability in the ImageIO framework used by Apple devices. ImageIO is responsible for decoding and processing mu ... Read more

-
TheCyberThrone
CVE-2018-0171 Years old Cisco Bug exploited
August 21, 2025The CVE-2018-0171 vulnerability is a critical security flaw in Cisco IOS and IOS XE software, specifically affecting the Smart Install feature, which is designed for easy deployment of ... Read more

-
Help Net Security
Russian threat actors using old Cisco bug to target critical infrastructure orgs
A threat group linked to the Russian Federal Security Service’s (FSB) Center 16 unit has been compromising unpatched and end-of-life Cisco networking devices via an old vulnerability (CVE-2018-0171), ... Read more

-
BleepingComputer
FBI warns of Russian hackers exploiting 7-year-old Cisco flaw
The Federal Bureau of Investigation (FBI) has warned that hackers linked to Russia's Federal Security Service (FSB) are targeting critical infrastructure organizations in attacks exploiting a 7-year-o ... Read more

-
CybersecurityNews
FBI Warns of Russian Government Hackers Attacking Networking Devices of Critical Infrastructure
The Federal Bureau of Investigation has issued a critical security alert regarding sophisticated cyber operations conducted by Russian Federal Security Service (FSB) Center 16, targeting networking in ... Read more

-
The Cyber Express
Russia’s FSB-Linked Hackers Targeting Cisco Network Gear Used in Critical Infrastructure
How often do you hear people talking about issues of legacy systems—especially in critical infrastructure environments? Here’s another example of how deeply rooted this issue is—legacy Cisco router in ... Read more

-
CybersecurityNews
Russian Hackers Exploiting 7-Year-Old Cisco Vulnerability to Collect Configs from Industrial Systems
A Russian state-sponsored cyber espionage group designated as Static Tundra has been actively exploiting a seven-year-old vulnerability in Cisco networking devices to steal configuration data and esta ... Read more

-
Daily CyberSecurity
AI’s Dark Side: How a New Website Builder Is Fueling a Surge in Cybercrime
Example CAPTCHA that redirects to banking credential phishing website | Image: Proofpoint Artificial intelligence is lowering the barrier to cybercrime. According to a new report by Proofpoint, threat ... Read more

-
Daily CyberSecurity
A Decade of Espionage: How a Russian APT Exploited Cisco Devices (CVE-2018-0171) for Years
Cisco Talos has released a new analysis exposing “Static Tundra,” a Russian state-sponsored threat actor that has been exploiting unpatched and end-of-life Cisco devices for more than a decade. The gr ... Read more

-
Hackread - Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Russian State Hackers Exploit 7-Year-Old Cisco Router Vulnerability
FBI and Cisco warn Russian hackers are exploiting a 7-year-old Cisco Smart Install vulnerability on outdated routers and switches worldwide. Thousands of outdated Cisco devices that no longer receive ... Read more

-
The Register
FBI: Russian spies exploiting a 7-year-old Cisco bug to slurp configs from critical infrastructure
The FBI and security researchers today warned that Russian government spies exploited a seven-year-old bug in end-of-life Cisco networking devices to snoop around in American critical infrastructure n ... Read more

-
The Hacker News
FBI Warns FSB-Linked Hackers Exploiting Unpatched Cisco Devices for Cyber Espionage
Aug 20, 2025Ravie LakshmananCyber Espionage / Vulnerability A Russian state-sponsored cyber espionage group known as Static Tundra has been observed actively exploiting a seven-year-old security fla ... Read more

-
security.nl
Cisco en FBI waarschuwen voor actief misbruik van 7 jaar oud Smart Install-lek
Cisco en de FBI waarschuwen organisaties vandaag voor actief misbruik van een 7 jaar oud beveiligingslek waarmee aanvallers netwerkapparaten op afstand kunnen overnemen. Updates voor de kwetsbaarheid, ... Read more

-
Daily CyberSecurity
Critical Cisco RCE Flaw (CVE-2025-20265, CVSS 10): Unauthenticated Attackers Can Hijack Firewalls
Cisco has disclosed a critical remote code execution vulnerability in its Secure Firewall Management Center (FMC) Software that could allow unauthenticated attackers to execute arbitrary commands with ... Read more

-
BleepingComputer
Chinese hackers breached National Guard to steal network configurations
The Chinese state-sponsored hacking group known as Salt Typhoon breached and remained undetected in a U.S. Army National Guard network for nine months in 2024, stealing network configuration files and ... Read more

-
The Hacker News
Chinese Hackers Target Taiwan's Semiconductor Sector with Cobalt Strike, Custom Backdoors
The Taiwanese semiconductor industry has become the target of spear-phishing campaigns undertaken by three Chinese state-sponsored threat actors. "Targets of these campaigns ranged from organizations ... Read more
The following table lists the changes that have been made to the
CVE-2018-0171
vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
Modified Analysis by [email protected]
Jan. 27, 2025
Action Type Old Value New Value -
CVE Modified by af854a3a-2127-422b-91ae-364da2661108
Nov. 21, 2024
Action Type Old Value New Value Added Reference http://www.securityfocus.com/bid/103538 Added Reference http://www.securitytracker.com/id/1040580 Added Reference https://ics-cert.us-cert.gov/advisories/ICSA-18-107-04 Added Reference https://ics-cert.us-cert.gov/advisories/ICSA-18-107-05 Added Reference https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2 Added Reference https://www.darkreading.com/perimeter/attackers-exploit-cisco-switch-issue-as-vendor-warns-of-yet-another-critical-flaw/d/d-id/1331490 -
CVE Modified by [email protected]
May. 14, 2024
Action Type Old Value New Value -
Modified Analysis by [email protected]
Sep. 04, 2020
Action Type Old Value New Value Removed CVSS V3 NIST AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Added CVSS V3.1 NIST AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Removed CWE NIST CWE-119 Removed CWE NIST CWE-20 Added CWE NIST CWE-787 -
CVE Modified by [email protected]
Oct. 09, 2019
Action Type Old Value New Value Added CWE Cisco Systems, Inc. CWE-20 -
Initial Analysis by [email protected]
Apr. 24, 2018
Action Type Old Value New Value Added CVSS V2 (AV:N/AC:L/Au:N/C:C/I:C/A:C) Added CVSS V3 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Changed Reference Type https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2 No Types Assigned https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2 Vendor Advisory Changed Reference Type https://ics-cert.us-cert.gov/advisories/ICSA-18-107-04 No Types Assigned https://ics-cert.us-cert.gov/advisories/ICSA-18-107-04 Third Party Advisory, US Government Resource Changed Reference Type http://www.securitytracker.com/id/1040580 No Types Assigned http://www.securitytracker.com/id/1040580 Third Party Advisory, VDB Entry Changed Reference Type https://ics-cert.us-cert.gov/advisories/ICSA-18-107-05 No Types Assigned https://ics-cert.us-cert.gov/advisories/ICSA-18-107-05 Third Party Advisory, US Government Resource Changed Reference Type https://www.darkreading.com/perimeter/attackers-exploit-cisco-switch-issue-as-vendor-warns-of-yet-another-critical-flaw/d/d-id/1331490 No Types Assigned https://www.darkreading.com/perimeter/attackers-exploit-cisco-switch-issue-as-vendor-warns-of-yet-another-critical-flaw/d/d-id/1331490 Press/Media Coverage Changed Reference Type http://www.securityfocus.com/bid/103538 No Types Assigned http://www.securityfocus.com/bid/103538 Third Party Advisory, VDB Entry Added CWE CWE-20 Added CWE CWE-119 Added CPE Configuration OR *cpe:2.3:o:cisco:ios:15.2\(5\)e:*:*:*:*:*:*:* -
CVE Modified by [email protected]
Apr. 20, 2018
Action Type Old Value New Value Added Reference https://ics-cert.us-cert.gov/advisories/ICSA-18-107-05 [No Types Assigned] Added Reference https://ics-cert.us-cert.gov/advisories/ICSA-18-107-04 [No Types Assigned] -
CVE Modified by [email protected]
Apr. 13, 2018
Action Type Old Value New Value Added Reference https://www.darkreading.com/perimeter/attackers-exploit-cisco-switch-issue-as-vendor-warns-of-yet-another-critical-flaw/d/d-id/1331490 [No Types Assigned] -
CVE Modified by [email protected]
Mar. 31, 2018
Action Type Old Value New Value Added Reference http://www.securityfocus.com/bid/103538 [No Types Assigned] -
CVE Modified by [email protected]
Mar. 30, 2018
Action Type Old Value New Value Added Reference http://www.securitytracker.com/id/1040580 [No Types Assigned]
Vulnerability Scoring Details
Base CVSS Score: 9.8
Base CVSS Score: 10
Exploit Prediction
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days.
93.41 }} 0.13%
score
0.99811
percentile