Vulnerability record · CVE-2018-0151 · published 28 March 2018
CVE-2018-0151: Cisco IOS/IOS XE QoS UDP Port 18999 Buffer Overflow
Cisco · Ios Xe
Cisco IOS and IOS XE contain a buffer overflow in the QoS subsystem caused by incorrect bounds checking of values in packets sent to UDP port 18999. An unauthenticated remote attacker can send crafted packets to trigger the overflow, leading to code execution with elevated privileges or a device reload. The flaw is critical because it is network-reachable without credentials and affects core routing and switching platforms.
Description
A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges. The vulnerability is due to incorrect bounds checking of certain values in packets that are destined for UDP port 18999 of an affected device. An attacker could exploit this vulnerability by sending malicious packets to an affected device. When the packets are processed, an exploitable buffer overflow condition may occur. A successful exploit could allow the attacker to execute arbitrary code on the affected device with elevated privileges. The attacker could also leverage this vulnerability to cause the device to reload, causing a temporary DoS condition while the device is reloading. The malicious packets must be destined to and processed by an affected device. Traffic transiting a device will not trigger the vulnerability. Cisco Bug IDs: CSCvf73881.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, unauthenticated remote code execution, and confirmed exploitation in CISA KEV make this a top remediation priority.
What it is
Cisco IOS and IOS XE contain a buffer overflow in the QoS subsystem caused by incorrect bounds checking of values in packets sent to UDP port 18999. An unauthenticated remote attacker can send crafted packets to trigger the overflow, leading to code execution with elevated privileges or a device reload. The flaw is critical because it is network-reachable without credentials and affects core routing and switching platforms.
Impact
An attacker can execute arbitrary code with elevated privileges on the affected device or force it to reload, causing a denial of service. Code execution on a network device can allow persistent control, traffic manipulation, or use as a pivot into the network.
Attack surface
The vulnerability is reached by sending malicious packets destined to UDP port 18999 on an affected device; the CVSS vector shows network access, no privileges, and no user interaction. Only traffic destined to and processed by the device triggers it, not traffic transiting the device.
Exploitation
CVE-2018-0151 is listed in CISA KEV with a 2022-03-03 addition date, indicating known exploitation in the wild. EPSS shows a 30-day probability of 0.14197 (96th percentile), and references include vendor and US government advisories.
What to do
- Apply the Cisco IOS/IOS XE updates referenced in the vendor advisory cisco-sa-20180328-qos as the primary fix.
- If immediate patching is not possible, restrict or block UDP port 18999 to affected devices using infrastructure ACLs or control-plane policing.
- Disable or restrict unnecessary QoS features and services on exposed devices where operationally feasible.
- Monitor Cisco security advisories and CISA KEV for updated guidance and ensure devices are not exposed to untrusted networks.
- Verify device integrity after suspected exploitation by checking for unexpected reloads, configuration changes, or unauthorized code.
Detection
- Monitor network traffic and firewall logs for UDP packets destined to port 18999 on Cisco IOS/IOS XE devices.
- Alert on unexpected device reloads or crashes in QoS-related processes on affected Cisco devices.
- Review device logs and syslog for QoS subsystem errors, buffer overflow indicators, or anomalous process behavior.
- Use network flow data to identify external hosts sending traffic to UDP 18999 on internal routing and switching infrastructure.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-0151 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 March 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/103540 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040582 | Third Party AdvisoryVDB Entry |
| https://ics-cert.us-cert.gov/advisories/ICSA-18-107-03 | Third Party AdvisoryUS Government Resource |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-qos | MitigationVendor Advisory |
| http://www.securityfocus.com/bid/103540 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040582 | Third Party AdvisoryVDB Entry |
| https://ics-cert.us-cert.gov/advisories/ICSA-18-107-03 | Third Party AdvisoryUS Government Resource |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-qos | MitigationVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-0151 | US Government Resource |
Track CVE-2018-0151 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-0151), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.