CISA Known Exploited Vulnerability

CVE-2018-0173

Cisco · IOS and IOS XE Software

Cisco IOS and IOS XE Software Improper Input Validation Vulnerability

Date added
BOD 22-01 due date
CWE CWE-20
Ransomware Unknown

CISA description

A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets can allow for denial-of-service (DoS).

Required action

Apply updates per vendor instructions.