Vulnerability record · CVE-2018-0154 · published 28 March 2018
CVE-2018-0154: Cisco IOS ISM-VPN crypto engine VPN traffic DoS
Cisco · Ios
The crypto engine in the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software mishandles VPN traffic, allowing an unauthenticated remote attacker to hang or crash the device. Because the module handles VPN termination, a successful attack removes remote-access connectivity for all users of the affected device.
Description
A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient handling of VPN traffic by the affected device. An attacker could exploit this vulnerability by sending crafted VPN traffic to an affected device. A successful exploit could allow the attacker to cause the affected device to hang or crash, resulting in a DoS condition. Cisco Bug IDs: CSCvd39267.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityIt is a remotely exploitable, unauthenticated availability flaw with confirmed exploitation in the wild, though it only causes denial of service and requires the specific ISM-VPN hardware.
What it is
The crypto engine in the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software mishandles VPN traffic, allowing an unauthenticated remote attacker to hang or crash the device. Because the module handles VPN termination, a successful attack removes remote-access connectivity for all users of the affected device.
Impact
An attacker can cause a full denial of service: the device hangs or crashes, disrupting VPN and any other traffic handled by the affected platform. There is no confidentiality or integrity impact; only availability is lost.
Attack surface
Reachable over the network via crafted VPN traffic sent to the affected device, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required, so any host that can send VPN packets to the device can attempt it.
Exploitation
CVE-2018-0154 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating exploitation in the wild; EPSS 30-day probability is about 7.1 percent (93.9th percentile). No public exploit code or ransomware use is documented in this record.
What to do
- Apply the Cisco IOS software update referenced in Cisco advisory cisco-sa-20180328-dos, prioritizing ISM-VPN modules.
- If patching cannot be done immediately, restrict VPN traffic to trusted source addresses with ACLs or infrastructure access control lists.
- Disable or remove the ISM-VPN module where it is not operationally required.
- Monitor Cisco security advisories for updated guidance and verify the fix against the specific IOS release in use.
Detection
- Alert on unexpected device reloads, crashes or hangs on routers with ISM-VPN modules, correlating with VPN traffic spikes.
- Monitor syslog and SNMP traps for crypto engine or VPN process failures and abnormal CPU/memory on affected devices.
- Baseline normal VPN peer addresses and flag crafted or malformed VPN packets from unexpected sources at the network edge.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-0154 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 March 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/103559 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040585 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-dos | Vendor Advisory |
| http://www.securityfocus.com/bid/103559 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040585 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-dos | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-0154 | US Government Resource |
Track CVE-2018-0154 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-0154), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.