LIVE NEWSROOM · --:-- · May 25, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2018-0173

CVE-2018-0173

Cisco IOS and IOS XE Software Improper Input Validation Vulnerability

CVSS 8.6 · HIGH ⚠ CISA KEV — ACTIVELY EXPLOITED
On the CISA KEV catalog

Confirmed exploited in the wild. Added 2022-03-03. Federal remediation due 2022-03-17.
Required action: Apply updates per vendor instructions.

Summary

A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a Relay Reply denial of service (DoS) condition. The vulnerability exists because the affected software performs incomplete input validation of encapsulated option 82 information that it receives in DHCPOFFER messages from DHCPv4 servers. An attacker could exploit this vulnerability by sending a crafted DHCPv4 packet to an affected device, which the device would then forward to a DHCPv4 server. When the affected software processes the option 82 information that is encapsulated in the response from the server, an error could occur. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvg62754.

CVSS 3.1 breakdown

Base score8.6 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Attack vectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeCHANGED
ConfidentialityNONE
IntegrityNONE
AvailabilityHIGH

Weakness type (CWE)

Affected products

Cisco iosCisco ios xeCisco 4321 integrated services routerCisco 4331 integrated services routerCisco 4351 integrated services routerCisco 4431 integrated services routerCisco 4451-x integrated services routerCisco asr 1000 series route processor \(rp2\)Cisco asr 1000 series route processor \(rp3\)Cisco asr 1001-hxCisco asr 1001-xCisco asr 1002-hxCisco asr 1002-xCisco cloud services router 1000vRockwellautomation allen-bradley armorstratix 5700Rockwellautomation allen-bradley stratix 5400Rockwellautomation allen-bradley stratix 5410Rockwellautomation allen-bradley stratix 5700Rockwellautomation allen-bradley stratix 8000Rockwellautomation allen-bradley stratix 8300
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD + CISA KEV. NVD last modified 2026-01-14. Always verify against the vendor advisory before acting.

Scroll to Top