CVE-2018-0171
Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability - [Actively Exploited]
Description
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute arbitrary code on an affected device. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted Smart Install message to an affected device on TCP port 4786. A successful exploit could allow the attacker to cause a buffer overflow on the affected device, which could have the following impacts: Triggering a reload of the device, Allowing the attacker to execute arbitrary code on the device, Causing an indefinite loop on the affected device that triggers a watchdog crash. Cisco Bug IDs: CSCvg76186.
INFO
Published Date :
March 28, 2018, 10:29 p.m.
Last Modified :
Jan. 27, 2025, 7:58 p.m.
Remotely Exploit :
Yes !
Source :
[email protected]
CISA KEV (Known Exploited Vulnerabilities)
For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild.
Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a denial-of-service (DoS) condition, or perform code execution on the affected device.
Apply updates per vendor instructions.
https://nvd.nist.gov/vuln/detail/CVE-2018-0171
CVSS Scores
Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
---|---|---|---|---|---|---|
CVSS 2.0 | HIGH | [email protected] | ||||
CVSS 3.1 | CRITICAL | [email protected] |
Solution
- Upgrade affected Cisco IOS and IOS XE Software to a fixed version.
- Refer to Cisco bug ID(s) CSCvg76186 for specific patched versions.
Public PoC/Exploit Available at Github
CVE-2018-0171 has a 13 public
PoC/Exploit
available at Github.
Go to the Public Exploits
tab to see the list.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2018-0171
.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2018-0171
is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2018-0171
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
None
Cisco SmartInstall Exploit [CVE-2018-0171]
cisco exploit cve-2018-0171 smartinstall
Python
None
Ostorlab KEV: One-command to detect most remotely known exploitable vulnerabilities. Sourced from CISA KEV, Google's Tsunami, Ostorlab's Asteroid and Bug Bounty programs.
cisa-kev vulnerability 0day cisa exploits
Automates searching CVEs in the Metasploit database of exploits.
Python
None
checking alerts of X-CERT
Go
None
Python
For novices
None
Python
A wrapper for Cisco's smi_check.py file.
Python
None
✍️ A curated list of CVE PoCs.
awesome cve poc
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2018-0171
vulnerability anywhere in the article.

-
SentinelOne
The Good, the Bad and the Ugly in Cybersecurity – Week 36
The Good | U.S. Puts $10m bounty on Heads of Three Russian FSB Threat Actors The U.S. Department of State has announced a bounty of up to $10 million for information on three Russian Federal Security ... Read more

-
SentinelOne
The Good, the Bad and the Ugly in Cybersecurity – Week 36
The Good | U.S. Puts $10m bounty on Heads of Three Russian FSB Threat Actors The U.S. Department of State has announced a bounty of up to $10 million for information on three Russian Federal Security ... Read more

-
CybersecurityNews
US Offers $10M Bounty For FSB Hackers Who Exploited Cisco Vulnerability To Attack Critical Infrastructure
The United States government has announced a reward of up to $10 million for information leading to the identification or location of three Russian intelligence officers. The bounty, offered through t ... Read more

-
CybersecurityNews
Chinese APT Hackers Exploit Router Vulnerabilities to Infiltrate Enterprise Environments
Over the past several years, a concerted campaign by Chinese state-sponsored Advanced Persistent Threat (APT) groups has exploited critical vulnerabilities in enterprise-grade routers to establish lon ... Read more

-
The Register
US puts $10M bounty on three Russians accused of attacking critical infrastructure
The US State Department has put a $10 million bounty on the heads of three Russians accused of being intelligence agents hacking America's critical infrastructure - primarily via old Cisco kit, it see ... Read more

-
BleepingComputer
US offers $10 million bounty for info on Russian FSB hackers
The U.S. Department of State is offering a reward of up to $10 million for information on three Russian Federal Security Service (FSB) officers involved in cyberattacks targeting U.S. critical infrast ... Read more

-
europa.eu
Cyber Brief 25-09 - August 2025
Cyber Brief (August 2025)September 2, 2025 - Version: 1TLP:CLEARExecutive summaryWe analysed 321 open source reports for this Cyber Brief1.Relating to cyber policy and law enforcement, Ukraine, Romani ... Read more

-
SentinelOne
The Good, the Bad and the Ugly in Cybersecurity – Week 35
The Good | Interpol Cracks Down on Cybercrime as U.S. Sanctions North Korean IT Scheme Interpol announced the arrest of over 1200 suspects in Operation Serengeti 2.0, a three-month crackdown on cyberc ... Read more

-
SentinelOne
The Good, the Bad and the Ugly in Cybersecurity – Week 35
The Good | Interpol Cracks Down on Cybercrime as U.S. Sanctions North Korean IT Scheme Interpol announced the arrest of over 1200 suspects in Operation Serengeti 2.0, a three-month crackdown on cyberc ... Read more

-
The Hacker News
Salt Typhoon Exploits Cisco, Ivanti, Palo Alto Flaws to Breach 600 Organizations Worldwide
The China-linked advanced persistent threat (APT) actor known as Salt Typhoon has continued its attacks targeting networks across the world, including organizations in the telecommunications, governme ... Read more

-
Hackread - Latest Cybersecurity, Hacking News, Tech, AI & Crypto
UK and US Blame Three Chinese Tech Firms for Global Cyberattacks
A coalition of international cybersecurity agencies led by the UK’s National Cyber Security Centre (NCSC) has publicly linked three China-based technology companies to a long-running global cyberattac ... Read more

-
CybersecurityNews
CISA Publish Hunting and Mitigation Guide to Defend Networks from Chinese State-Sponsored Actors
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), alongside the NSA, FBI, and a broad coalition of international partners, has released a comprehensive cybersecurity advisory detailing ... Read more

-
The Register
If you thought China's Salt Typhoon was booted off critical networks, think again
China's Salt Typhoon cyberspies continue their years-long hacking campaign targeting critical industries around the world, according to a joint security alert from cyber and law enforcement agencies a ... Read more

-
Daily CyberSecurity
An Espionage System: NSA, CISA, & Partners Expose Chinese APT Groups
In a multinational alert, the U.S. National Security Agency (NSA), CISA, FBI, and partners from more than a dozen allied nations have released a Joint Cybersecurity Advisory (CSA) exposing how Chinese ... Read more

-
BleepingComputer
Global Salt Typhoon hacking campaigns linked to Chinese tech firms
The U.S. National Security Agency (NSA), the UK's National Cyber Security Centre (NCSC), and partners from over a dozen countries have linked the Salt Typhoon global hacking campaigns to three China-b ... Read more

-
CybersecurityNews
Weekly Cybersecurity News Recap : Apple 0-day, Chrome, Copilot Vulnerabilities and Cyber Attacks
This past week was packed with high-severity disclosures and active exploitation reports across the global threat landscape. At the forefront, Apple rushed out emergency patches for yet another zero-d ... Read more

-
Help Net Security
Week in review: Covertly connected and insecure Android VPN apps, Apple fixes exploited zero-day
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Android VPN apps used by millions are covertly connected AND insecure Three families of Android VPN ap ... Read more

-
Help Net Security
China-linked Murky Panda targets and moves laterally through cloud services
In its recently released 2025 Threat Hunting Report, Crowdstrike pointed out an interesting trend: a 136% surge in cloud intrusions. A good chunk of this surge is due to “China-nexus adversaries”, Mur ... Read more

-
Help Net Security
AI gives ransomware gangs a deadly upgrade
Ransomware continues to be the major threat to large and medium-sized businesses, with numerous ransomware gangs abusing AI for automation, according to Acronis. Ransomware gangs maintain pressure on ... Read more

-
TheCyberThrone
CVE-2025-43300 affects Apple Products
August 22, 2025Vulnerability SummaryCVE-2025-43300 is a zero-day out-of-bounds write vulnerability in the ImageIO framework used by Apple devices. ImageIO is responsible for decoding and processing mu ... Read more
The following table lists the changes that have been made to the
CVE-2018-0171
vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
Modified Analysis by [email protected]
Jan. 27, 2025
Action Type Old Value New Value -
CVE Modified by af854a3a-2127-422b-91ae-364da2661108
Nov. 21, 2024
Action Type Old Value New Value Added Reference http://www.securityfocus.com/bid/103538 Added Reference http://www.securitytracker.com/id/1040580 Added Reference https://ics-cert.us-cert.gov/advisories/ICSA-18-107-04 Added Reference https://ics-cert.us-cert.gov/advisories/ICSA-18-107-05 Added Reference https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2 Added Reference https://www.darkreading.com/perimeter/attackers-exploit-cisco-switch-issue-as-vendor-warns-of-yet-another-critical-flaw/d/d-id/1331490 -
CVE Modified by [email protected]
May. 14, 2024
Action Type Old Value New Value -
Modified Analysis by [email protected]
Sep. 04, 2020
Action Type Old Value New Value Removed CVSS V3 NIST AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Added CVSS V3.1 NIST AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Removed CWE NIST CWE-119 Removed CWE NIST CWE-20 Added CWE NIST CWE-787 -
CVE Modified by [email protected]
Oct. 09, 2019
Action Type Old Value New Value Added CWE Cisco Systems, Inc. CWE-20 -
Initial Analysis by [email protected]
Apr. 24, 2018
Action Type Old Value New Value Added CVSS V2 (AV:N/AC:L/Au:N/C:C/I:C/A:C) Added CVSS V3 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Changed Reference Type https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2 No Types Assigned https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2 Vendor Advisory Changed Reference Type https://ics-cert.us-cert.gov/advisories/ICSA-18-107-04 No Types Assigned https://ics-cert.us-cert.gov/advisories/ICSA-18-107-04 Third Party Advisory, US Government Resource Changed Reference Type http://www.securitytracker.com/id/1040580 No Types Assigned http://www.securitytracker.com/id/1040580 Third Party Advisory, VDB Entry Changed Reference Type https://ics-cert.us-cert.gov/advisories/ICSA-18-107-05 No Types Assigned https://ics-cert.us-cert.gov/advisories/ICSA-18-107-05 Third Party Advisory, US Government Resource Changed Reference Type https://www.darkreading.com/perimeter/attackers-exploit-cisco-switch-issue-as-vendor-warns-of-yet-another-critical-flaw/d/d-id/1331490 No Types Assigned https://www.darkreading.com/perimeter/attackers-exploit-cisco-switch-issue-as-vendor-warns-of-yet-another-critical-flaw/d/d-id/1331490 Press/Media Coverage Changed Reference Type http://www.securityfocus.com/bid/103538 No Types Assigned http://www.securityfocus.com/bid/103538 Third Party Advisory, VDB Entry Added CWE CWE-20 Added CWE CWE-119 Added CPE Configuration OR *cpe:2.3:o:cisco:ios:15.2\(5\)e:*:*:*:*:*:*:* -
CVE Modified by [email protected]
Apr. 20, 2018
Action Type Old Value New Value Added Reference https://ics-cert.us-cert.gov/advisories/ICSA-18-107-05 [No Types Assigned] Added Reference https://ics-cert.us-cert.gov/advisories/ICSA-18-107-04 [No Types Assigned] -
CVE Modified by [email protected]
Apr. 13, 2018
Action Type Old Value New Value Added Reference https://www.darkreading.com/perimeter/attackers-exploit-cisco-switch-issue-as-vendor-warns-of-yet-another-critical-flaw/d/d-id/1331490 [No Types Assigned] -
CVE Modified by [email protected]
Mar. 31, 2018
Action Type Old Value New Value Added Reference http://www.securityfocus.com/bid/103538 [No Types Assigned] -
CVE Modified by [email protected]
Mar. 30, 2018
Action Type Old Value New Value Added Reference http://www.securitytracker.com/id/1040580 [No Types Assigned]
Vulnerability Scoring Details
Base CVSS Score: 9.8
Base CVSS Score: 10
Exploit Prediction
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days.
93.12 }} -0.27%
score
0.99783
percentile