LIVE NEWSROOM · --:-- · May 24, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2018-0161

CVE-2018-0161

Cisco IOS Software Resource Management Errors Vulnerability

CVSS 6.3 · MEDIUM ⚠ CISA KEV — ACTIVELY EXPLOITED
On the CISA KEV catalog

Confirmed exploited in the wild. Added 2022-03-03. Federal remediation due 2022-03-17.
Required action: Apply updates per vendor instructions.

Summary

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial of service (DoS) condition, aka a GET MIB Object ID Denial of Service Vulnerability. The vulnerability is due to a condition that could occur when the affected software processes an SNMP read request that contains a request for the ciscoFlashMIB object ID (OID). An attacker could trigger this vulnerability by issuing an SNMP GET request for the ciscoFlashMIB OID on an affected device. A successful exploit could cause the affected device to restart due to a SYS-3-CPUHOG. This vulnerability affects the following Cisco devices if they are running a vulnerable release of Cisco IOS Software and are configured to use SNMP Version 2 (SNMPv2) or SNMP Version 3 (SNMPv3): Cisco Catalyst 2960-L Series Switches, Cisco Catalyst Digital Building Series Switches 8P, Cisco Catalyst Digital Building Series Switches 8U. Cisco Bug IDs: CSCvd89541.

CVSS 3.1 breakdown

Base score6.3 (MEDIUM)
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H
Attack vectorNETWORK
Attack complexityHIGH
Privileges requiredLOW
User interactionNONE
ScopeCHANGED
ConfidentialityNONE
IntegrityNONE
AvailabilityHIGH

Weakness type (CWE)

Affected products

Cisco iosCisco catalyst 2960l-16ps-llCisco catalyst 2960l-16ts-llCisco catalyst 2960l-24pq-llCisco catalyst 2960l-24ps-llCisco catalyst 2960l-24tq-llCisco catalyst 2960l-24ts-llCisco catalyst 2960l-48pq-llCisco catalyst 2960l-48ps-llCisco catalyst 2960l-48tq-llCisco catalyst 2960l-48ts-llCisco catalyst 2960l-8ps-llCisco catalyst 2960l-8ts-llCisco catalyst digital building series switches-8pCisco catalyst digital building series switches-8u
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD + CISA KEV. NVD last modified 2026-01-14. Always verify against the vendor advisory before acting.

Scroll to Top