LIVE NEWSROOM · --:-- · May 24, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2018-0159

CVE-2018-0159

Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability

CVSS 7.5 · HIGH ⚠ CISA KEV — ACTIVELY EXPLOITED
On the CISA KEV catalog

Confirmed exploited in the wild. Added 2022-03-03. Federal remediation due 2022-03-17.
Required action: Apply updates per vendor instructions.

Summary

A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of specific IKEv1 packets. An attacker could exploit this vulnerability by sending crafted IKEv1 packets to an affected device during an IKE negotiation. A successful exploit could allow the attacker to cause an affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCuj73916.

CVSS 3.1 breakdown

Base score7.5 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack vectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
IntegrityNONE
AvailabilityHIGH

Weakness type (CWE)

Affected products

Cisco iosCisco asr 901-12c-f-dCisco asr 901-12c-ft-dCisco asr 901-4c-f-dCisco asr 901-4c-ft-dCisco asr 901-6cz-f-aCisco asr 901-6cz-f-dCisco asr 901-6cz-ft-aCisco asr 901-6cz-ft-dCisco me 3600x-24cx-mCisco me 3600x-24fs-mCisco me 3600x-24ts-mCisco me 3800x-24fs-mCisco ios xe
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD + CISA KEV. NVD last modified 2026-01-14. Always verify against the vendor advisory before acting.

Scroll to Top