CVE-2018-0167: Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCuo17183, CSCvd73487.
Other sources
There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software which could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-0167?
CVE-2018-0167 is a vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS XR and XE Software that could allow an unauthenticated attacker to cause a denial of service (DoS) or execute arbitrary code.
Who is affected by CVE-2018-0167?
Cisco IOS, XR, and XE Software versions 5.2.0.base are affected by CVE-2018-0167.
How severe is CVE-2018-0167?
CVE-2018-0167 has a severity rating of 8.8, which is considered high.
How can I fix CVE-2018-0167?
Update to a fixed version of Cisco IOS, XR, or XE Software as recommended by Cisco.
Where can I find more information about CVE-2018-0167?
You can find more information about CVE-2018-0167 on the following websites: [SecurityFocus](http://www.securityfocus.com/bid/103564), [SecurityTracker](http://www.securitytracker.com/id/1040586), [ICS-CERT](https://ics-cert.us-cert.gov/advisories/ICSA-18-107-03).