CVE-2018-0171
Cisco IOS and IOS XE Software Smart Install Remote - [Actively Exploited]
Description
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute arbitrary code on an affected device. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted Smart Install message to an affected device on TCP port 4786. A successful exploit could allow the attacker to cause a buffer overflow on the affected device, which could have the following impacts: Triggering a reload of the device, Allowing the attacker to execute arbitrary code on the device, Causing an indefinite loop on the affected device that triggers a watchdog crash. Cisco Bug IDs: CSCvg76186.
INFO
Published Date :
March 28, 2018, 10:29 p.m.
Last Modified :
Jan. 27, 2025, 7:58 p.m.
Source :
[email protected]
Remotely Exploitable :
Yes !
Impact Score :
5.9
Exploitability Score :
3.9
CISA KEV (Known Exploited Vulnerabilities)
For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild.
Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a denial-of-service (DoS) condition, or perform code execution on the affected device.
Apply updates per vendor instructions.
https://nvd.nist.gov/vuln/detail/CVE-2018-0171
Public PoC/Exploit Available at Github
CVE-2018-0171 has a 12 public PoC/Exploit
available at Github.
Go to the Public Exploits
tab to see the list.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2018-0171
.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Cisco SmartInstall Exploit [CVE-2018-0171]
cisco exploit cve-2018-0171 smartinstall
Python
None
Ostorlab KEV: One-command to detect most remotely known exploitable vulnerabilities. Sourced from CISA KEV, Google's Tsunami, Ostorlab's Asteroid and Bug Bounty programs.
cisa-kev vulnerability 0day cisa exploits
Automates searching CVEs in the Metasploit database of exploits.
Python
None
checking alerts of X-CERT
Go
None
Python
For novices
None
Python
A wrapper for Cisco's smi_check.py file.
Python
None
✍️ A curated list of CVE PoCs.
awesome cve poc
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2018-0171
vulnerability anywhere in the article.

-
The Hacker News
Amnesty Finds Cellebrite’s Zero-Day Used to Unlock Serbian Activist’s Android Phone
Mobile Security / Zero-Day A 23-year-old Serbian youth activist had their Android phone targeted by a zero-day exploit developed by Cellebrite to unlock the device, according to a new report from Amne ... Read more

-
The Hacker News
RDP: a Double-Edged Sword for IT Teams – Essential Yet Exploitable
Remote Desktop Protocol (RDP) is an amazing technology developed by Microsoft that lets you access and control another computer over a network. It's like having your office computer with you wherever ... Read more

-
The Hacker News
PolarEdge Botnet Exploits Cisco and Other Flaws to Hijack ASUS, QNAP, and Synology Devices
A new malware campaign has been observed targeting edge devices from Cisco, ASUS, QNAP, and Synology to rope them into a botnet named PolarEdge since at least the end of 2023. French cybersecurity com ... Read more

-
The Hacker News
Hackers Exploited Krpano Framework Flaw to Inject Spam Ads on 350+ Websites
A cross-site scripting (XSS) vulnerability in a virtual tour framework has been weaponized by malicious actors to inject malicious scripts across hundreds of websites with the goal of manipulating sea ... Read more

-
The Hacker News
Leaked Black Basta Chat Logs Reveal $107M Ransom Earnings and Internal Power Struggles
More than a year's worth of internal chat logs from a ransomware gang known as Black Basta have been published online in a leak that provides unprecedented visibility into their tactics and internal c ... Read more

-
The Hacker News
CERT-UA Warns of UAC-0173 Attacks Deploying DCRat to Compromise Ukrainian Notaries
Network Security / Threat Intelligence The Computer Emergency Response Team of Ukraine (CERT-UA) on Tuesday warned of renewed activity from an organized criminal group it tracks as UAC-0173 that invol ... Read more

-
The Hacker News
CISA Adds Microsoft and Zimbra Flaws to KEV Catalog Amid Active Exploitation
Enterprise Security / Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday placed two security flaws impacting Microsoft Partner Center and Synacor Zimbra Collabor ... Read more

-
security.nl
Securitybedrijf meldt actief misbruik van jarenoude Cisco-kwetsbaarheden
Aanvallers maken actief misbruik van jarenoude kwetsbaarheden in apparatuur van Cisco, waaronder een kritiek beveiligingslek dat sinds 28 maart 2018 bekend is. Dat laat securitybedrijf GreyNoise op ba ... Read more

-
Cyber Security News
100+ Malicious IPs Actively Exploiting Vulnerabilities in Cisco Devices
A malicious campaign targeting Cisco networking equipment through two critical vulnerabilities, with state-backed actors and other actors exploiting unpatched systems. GreyNoise Intelligence has ident ... Read more

-
The Hacker News
Two Actively Exploited Security Flaws in Adobe and Oracle Products Flagged by CISA
Network Security / Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two security flaws impacting Adobe ColdFusion and Oracle Agile Product Lifecycle Management ... Read more

-
The Hacker News
New Malware Campaign Uses Cracked Software to Spread Lumma and ACR Stealer
Endpoint Security / Vulnerability Cybersecurity researchers are warning of a new campaign that leverages cracked versions of software as a lure to distribute information stealers like Lumma and ACR St ... Read more

-
TheCyberThrone
Cisco detailed Salt Typhoon Attack on Telecom Networks
The Salt Typhoon cyber espionage campaign has been meticulously analyzed by Cisco Talos, revealing a highly sophisticated operation targeting global telecommunications networks. This campaign, attribu ... Read more

-
Cyber Security News
Salt Typhoon Hackers Exploit Cisco Vulnerability To Gain Access To U.S. Telecom Networks
Cisco Talos has uncovered a sophisticated cyberespionage campaign by the state-aligned “Salt Typhoon” group targeting U.S. telecommunications infrastructure since late 2024. While credential theft rem ... Read more

-
Dark Reading
Cisco Confirms Salt Typhoon Exploitation in Telecom Hits
Source: Geopix / Alamy Stock PhotoNEWS BRIEFFollowing research reports last week that Salt Typhoon, the Chinese threat actor known for spying on communications networks, exploited a Cisco vulnerabilit ... Read more

-
Krypt3ia
Krypt3ia Daily Cyber Threat Intelligence (CTI) Digest
Date: 2.21.25 Top Headlines Firing of 130 CISA staff worries cybersecurity industry Summary: The firing of upwards of 130 cybersecurity professionals at the US Cybersecurity and Infrastructure Securit ... Read more

-
The Hacker News
Cisco Confirms Salt Typhoon Exploited CVE-2018-0171 to Target U.S. Telecom Networks
Network Security / Vulnerability Cisco has confirmed that a Chinese threat actor known as Salt Typhoon gained access by likely abusing a known security flaw tracked as CVE-2018-0171, and by obtaining ... Read more

-
BleepingComputer
Chinese hackers use custom malware to spy on US telecom networks
The Chinese state-sponsored Salt Typhoon hacking group uses a custom utility called JumbledPath to stealthily monitor network traffic and potentially capture sensitive data in cyberattacks on U.S. tel ... Read more

-
security.nl
Cisco: inbraak systemen telecomproviders via gestolen inloggegevens
Een groep aanvallers die op de Cisco-systemen van Amerikaanse telecomproviders wist in te breken maakte gebruik van gestolen inloggegevens, zo stelt Cisco. In een analyse laat het netwerkbedrijf weten ... Read more
The following table lists the changes that have been made to the
CVE-2018-0171
vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
Modified Analysis by [email protected]
Jan. 27, 2025
Action Type Old Value New Value -
CVE Modified by af854a3a-2127-422b-91ae-364da2661108
Nov. 21, 2024
Action Type Old Value New Value Added Reference http://www.securityfocus.com/bid/103538 Added Reference http://www.securitytracker.com/id/1040580 Added Reference https://ics-cert.us-cert.gov/advisories/ICSA-18-107-04 Added Reference https://ics-cert.us-cert.gov/advisories/ICSA-18-107-05 Added Reference https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2 Added Reference https://www.darkreading.com/perimeter/attackers-exploit-cisco-switch-issue-as-vendor-warns-of-yet-another-critical-flaw/d/d-id/1331490 -
CVE Modified by [email protected]
May. 14, 2024
Action Type Old Value New Value -
Modified Analysis by [email protected]
Sep. 04, 2020
Action Type Old Value New Value Removed CVSS V3 NIST AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Added CVSS V3.1 NIST AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Removed CWE NIST CWE-119 Removed CWE NIST CWE-20 Added CWE NIST CWE-787 -
CVE Modified by [email protected]
Oct. 09, 2019
Action Type Old Value New Value Added CWE Cisco Systems, Inc. CWE-20 -
Initial Analysis by [email protected]
Apr. 24, 2018
Action Type Old Value New Value Added CVSS V2 (AV:N/AC:L/Au:N/C:C/I:C/A:C) Added CVSS V3 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Changed Reference Type https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2 No Types Assigned https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2 Vendor Advisory Changed Reference Type https://ics-cert.us-cert.gov/advisories/ICSA-18-107-04 No Types Assigned https://ics-cert.us-cert.gov/advisories/ICSA-18-107-04 Third Party Advisory, US Government Resource Changed Reference Type http://www.securitytracker.com/id/1040580 No Types Assigned http://www.securitytracker.com/id/1040580 Third Party Advisory, VDB Entry Changed Reference Type https://ics-cert.us-cert.gov/advisories/ICSA-18-107-05 No Types Assigned https://ics-cert.us-cert.gov/advisories/ICSA-18-107-05 Third Party Advisory, US Government Resource Changed Reference Type https://www.darkreading.com/perimeter/attackers-exploit-cisco-switch-issue-as-vendor-warns-of-yet-another-critical-flaw/d/d-id/1331490 No Types Assigned https://www.darkreading.com/perimeter/attackers-exploit-cisco-switch-issue-as-vendor-warns-of-yet-another-critical-flaw/d/d-id/1331490 Press/Media Coverage Changed Reference Type http://www.securityfocus.com/bid/103538 No Types Assigned http://www.securityfocus.com/bid/103538 Third Party Advisory, VDB Entry Added CWE CWE-20 Added CWE CWE-119 Added CPE Configuration OR *cpe:2.3:o:cisco:ios:15.2\(5\)e:*:*:*:*:*:*:* -
CVE Modified by [email protected]
Apr. 20, 2018
Action Type Old Value New Value Added Reference https://ics-cert.us-cert.gov/advisories/ICSA-18-107-05 [No Types Assigned] Added Reference https://ics-cert.us-cert.gov/advisories/ICSA-18-107-04 [No Types Assigned] -
CVE Modified by [email protected]
Apr. 13, 2018
Action Type Old Value New Value Added Reference https://www.darkreading.com/perimeter/attackers-exploit-cisco-switch-issue-as-vendor-warns-of-yet-another-critical-flaw/d/d-id/1331490 [No Types Assigned] -
CVE Modified by [email protected]
Mar. 31, 2018
Action Type Old Value New Value Added Reference http://www.securityfocus.com/bid/103538 [No Types Assigned] -
CVE Modified by [email protected]
Mar. 30, 2018
Action Type Old Value New Value Added Reference http://www.securitytracker.com/id/1040580 [No Types Assigned]
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2018-0171
is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2018-0171
weaknesses.
Exploit Prediction
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days.
80.73 }} -9.90%
score
0.99096
percentile