Vulnerability Name:

CVE-2018-0179 (CCN-140922)

Assigned:2017-11-27
Published:2018-03-28
Updated:2019-10-09
Summary:Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Cisco Bug IDs: CSCuy32360, CSCuz60599.
CVSS v3 Severity:5.9 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
6.8 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H)
5.9 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:7.1 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
5.4 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2018-0179

Source: BID
Type: Third Party Advisory, VDB Entry
103556

Source: CCN
Type: BID-103556
Cisco IOS Login Enhancements Feature Multiple Denial of Service Vulnerabilities

Source: XF
Type: UNKNOWN
cisco-slogin-cve20180179-dos(140922)

Source: CCN
Type: Cisco Security Advisory cisco-sa-20180328-slogin
Cisco IOS Software Login Enhancements Login Block Denial of Service Vulnerabilities

Source: CONFIRM
Type: Vendor Advisory
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-slogin

Source: CCN
Type: CYBERSECURITY & INFRASTRUCTURE SECURITY AGENCY
KNOWN EXPLOITED VULNERABILITIES CATALOG

Vulnerable Configuration:Configuration 1:
  • cpe:/o:cisco:ios:15.3(0.0.19)sy:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:15.4(1)ia1.100:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:15.6(1.22)t:*:*:*:*:*:*:*
  • AND
  • cpe:/h:cisco:1921:-:*:*:*:*:*:*:*
  • OR cpe:/h:cisco:1941:-:*:*:*:*:*:*:*
  • OR cpe:/h:cisco:1941w:-:*:*:*:*:*:*:*
  • OR cpe:/h:cisco:2901:-:*:*:*:*:*:*:*
  • OR cpe:/h:cisco:2911:-:*:*:*:*:*:*:*
  • OR cpe:/h:cisco:2921:-:*:*:*:*:*:*:*
  • OR cpe:/h:cisco:2951:-:*:*:*:*:*:*:*
  • OR cpe:/h:cisco:3925:-:*:*:*:*:*:*:*
  • OR cpe:/h:cisco:3925e:-:*:*:*:*:*:*:*
  • OR cpe:/h:cisco:3945:-:*:*:*:*:*:*:*
  • OR cpe:/h:cisco:3945e:-:*:*:*:*:*:*:*
  • OR cpe:/h:cisco:4451-x:-:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:cisco:ios:15.3(0.0.19)sy:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:15.4(3)m4.1:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:cisco:ios:*:*:*:*:*:*:*:* (Version >= 15.4(2)cg
  • OR cpe:/o:cisco:ios:15.4(2)t:*:*:*:*:*:*:*
  • OR cpe:/o:cisco:ios:15.4(3)m:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    cisco ios 15.3(0.0.19)sy
    cisco ios 15.4(1)ia1.100
    cisco ios 15.6(1.22)t
    cisco 1921 -
    cisco 1941 -
    cisco 1941w -
    cisco 2901 -
    cisco 2911 -
    cisco 2921 -
    cisco 2951 -
    cisco 3925 -
    cisco 3925e -
    cisco 3945 -
    cisco 3945e -
    cisco 4451-x -
    cisco ios 15.3(0.0.19)sy
    cisco ios 15.4(3)m4.1
    cisco ios *
    cisco ios 15.4(2)t
    cisco ios 15.4(3)m