← Vulnerability feed

Vulnerability record · CVE-2018-0151 · published 28 March 2018

CVE-2018-0151: Cisco IOS/IOS XE QoS UDP Port 18999 Buffer Overflow

Cisco · Ios Xe

Cisco IOS and IOS XE contain a buffer overflow in the QoS subsystem caused by incorrect bounds checking of values in packets sent to UDP port 18999. An unauthenticated remote attacker can send crafted packets to trigger the overflow, leading to code execution with elevated privileges or a device reload. The flaw is critical because it is network-reachable without credentials and affects core routing and switching platforms.

9.8 CVSS 3.1 Critical CISA KEV since 3 Mar 2022 EPSS 14% · top 3.5% CWE-119 · Memory buffer overflow
9.8CVSS 3.1 base score, v2 10.0
14%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
9References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges. The vulnerability is due to incorrect bounds checking of certain values in packets that are destined for UDP port 18999 of an affected device. An attacker could exploit this vulnerability by sending malicious packets to an affected device. When the packets are processed, an exploitable buffer overflow condition may occur. A successful exploit could allow the attacker to execute arbitrary code on the affected device with elevated privileges. The attacker could also leverage this vulnerability to cause the device to reload, causing a temporary DoS condition while the device is reloading. The malicious packets must be destined to and processed by an affected device. Traffic transiting a device will not trigger the vulnerability. Cisco Bug IDs: CSCvf73881.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, unauthenticated remote code execution, and confirmed exploitation in CISA KEV make this a top remediation priority.

What it is

Cisco IOS and IOS XE contain a buffer overflow in the QoS subsystem caused by incorrect bounds checking of values in packets sent to UDP port 18999. An unauthenticated remote attacker can send crafted packets to trigger the overflow, leading to code execution with elevated privileges or a device reload. The flaw is critical because it is network-reachable without credentials and affects core routing and switching platforms.

Impact

An attacker can execute arbitrary code with elevated privileges on the affected device or force it to reload, causing a denial of service. Code execution on a network device can allow persistent control, traffic manipulation, or use as a pivot into the network.

Attack surface

The vulnerability is reached by sending malicious packets destined to UDP port 18999 on an affected device; the CVSS vector shows network access, no privileges, and no user interaction. Only traffic destined to and processed by the device triggers it, not traffic transiting the device.

Exploitation

CVE-2018-0151 is listed in CISA KEV with a 2022-03-03 addition date, indicating known exploitation in the wild. EPSS shows a 30-day probability of 0.14197 (96th percentile), and references include vendor and US government advisories.

What to do

  • Apply the Cisco IOS/IOS XE updates referenced in the vendor advisory cisco-sa-20180328-qos as the primary fix.
  • If immediate patching is not possible, restrict or block UDP port 18999 to affected devices using infrastructure ACLs or control-plane policing.
  • Disable or restrict unnecessary QoS features and services on exposed devices where operationally feasible.
  • Monitor Cisco security advisories and CISA KEV for updated guidance and ensure devices are not exposed to untrusted networks.
  • Verify device integrity after suspected exploitation by checking for unexpected reloads, configuration changes, or unauthorized code.

Detection

  • Monitor network traffic and firewall logs for UDP packets destined to port 18999 on Cisco IOS/IOS XE devices.
  • Alert on unexpected device reloads or crashes in QoS-related processes on affected Cisco devices.
  • Review device logs and syslog for QoS subsystem errors, buffer overflow indicators, or anomalous process behavior.
  • Use network flow data to identify external hosts sending traffic to UDP 18999 on internal routing and switching infrastructure.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-0151 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 March 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-0151 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2023-20198Cisco IOS XE Web UI unauthenticated privilege escalation and implant deploymentCVE-2023-20198 is a critical flaw in the Cisco IOS XE web UI that lets an unauthenticated remote attacker gain initial access and create a local priv…KEVEPSS 100%analysed9.8CVE-2017-3881Cisco IOS/IOS XE CMP Telnet Option Handling RCECisco IOS and IOS XE fail to restrict CMP-specific Telnet options to internal cluster communications and mishandle malformed CMP Telnet options, so a…KEVEPSS 99%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.8CVE-2017-6736Cisco IOS and IOS XE SNMP buffer overflow remote code executionThe SNMP subsystem in Cisco IOS and IOS XE contains a buffer overflow that can be triggered by a crafted SNMP packet sent over IPv4 or IPv6. It affec…KEVEPSS 70%analysed8.8CVE-2017-6737Cisco IOS and IOS XE SNMP Buffer Overflow RCECisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMPv1, v2c, and v3. An authenticated remote attacker who know…KEVEPSS 45%analysed8.8CVE-2017-6738Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionThe SNMP subsystem in Cisco IOS and IOS XE Software contains a buffer overflow that affects SNMP versions 1, 2c, and 3. An authenticated remote attac…KEVEPSS 11%analysed8.8CVE-2017-6739Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionCisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMP versions 1, 2c, and 3. A remote attacker who knows the SN…KEVEPSS 11%analysed8.8CVE-2017-6740Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionCisco IOS and IOS XE contain a buffer overflow in the SNMP subsystem affecting SNMP versions 1, 2c, and 3. An authenticated remote attacker can send …KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-2018-0151), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.