Loading HuntDB...

Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability

Added March 3, 2022 Due March 17, 2022 CVE-2018-0158
Overdue Cisco / IOS Software and Cisco IOS XE Software CWE-20

Description

A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition.

Required Action

Apply updates per vendor instructions.

References

Additional Information

Catalog Version
2025.01.24
Catalog Released
Jan. 24, 2025
Days Until Due
0 days
Last Updated
7 months, 3 weeks ago