← Vulnerability feed

Vulnerability record · CVE-2018-0155 · published 28 March 2018

CVE-2018-0155: Cisco Catalyst BFD offload incomplete header handling denial of service

Cisco · Ios

Cisco Catalyst 4500 and 4500-X series switches mishandle incomplete BFD headers in the BFD offload implementation, causing the iosd process to crash. An unauthenticated remote attacker can send a crafted BFD packet to or across an affected switch and force a system reload, disrupting all traffic through the device.

8.6 CVSS 3.1 High CISA KEV since 3 Mar 2022 EPSS 7.7% · top 5.6% CWE-388 · CWE-388CWE-755 · CWE-755
8.6CVSS 3.1 base score, v2 7.8
7.7%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
9References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial of service (DoS) condition. The vulnerability is due to insufficient error handling when the BFD header in a BFD packet is incomplete. An attacker could exploit this vulnerability by sending a crafted BFD message to or across an affected switch. A successful exploit could allow the attacker to trigger a reload of the system. This vulnerability affects Catalyst 4500 Supervisor Engine 6-E (K5), Catalyst 4500 Supervisor Engine 6L-E (K10), Catalyst 4500 Supervisor Engine 7-E (K10), Catalyst 4500 Supervisor Engine 7L-E (K10), Catalyst 4500E Supervisor Engine 8-E (K10), Catalyst 4500E Supervisor Engine 8L-E (K10), Catalyst 4500E Supervisor Engine 9-E (K10), Catalyst 4500-X Series Switches (K10), Catalyst 4900M Switch (K5), Catalyst 4948E Ethernet Switch (K5). Cisco Bug IDs: CSCvc40729.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw is remotely exploitable without authentication, causes full device denial of service, and is listed in CISA KEV as exploited in the wild.

What it is

Cisco Catalyst 4500 and 4500-X series switches mishandle incomplete BFD headers in the BFD offload implementation, causing the iosd process to crash. An unauthenticated remote attacker can send a crafted BFD packet to or across an affected switch and force a system reload, disrupting all traffic through the device.

Impact

The attacker gains no code execution or data access; the outcome is a denial of service in which the switch reloads and forwarding is interrupted. Because the flaw is in the core iosd process, the whole device is affected rather than a single interface.

Attack surface

Reachable over the network via crafted BFD packets sent to or across the switch, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required, and the scope change (S:C) reflects impact beyond the vulnerable component.

Exploitation

CVE-2018-0155 is listed in CISA KEV with a 2022-03-03 addition date, indicating known exploitation in the wild, and EPSS shows a 30-day probability of 0.07742 (94th percentile). No ransomware campaign use is recorded.

What to do

  • Apply the Cisco vendor advisory updates for the listed Catalyst 4500/4500-X supervisor engines and 4900/4948E switches.
  • If BFD is not required, disable BFD offload or BFD on affected interfaces to remove the attack path.
  • Restrict BFD traffic to trusted network segments with ACLs or infrastructure ACLs where operationally feasible.
  • Monitor for unexpected switch reloads and treat repeated iosd crashes as a possible exploitation attempt.

Detection

  • Alert on unexpected reloads or iosd process crashes on Catalyst 4500/4500-X platforms and correlate with BFD traffic.
  • Inspect BFD packet captures for malformed or truncated BFD headers arriving from untrusted sources.
  • Review syslog and SNMP traps for reload causes and BFD-related error messages around the time of a restart.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-0155 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 March 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-0155 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2023-20198Cisco IOS XE Web UI unauthenticated privilege escalation and implant deploymentCVE-2023-20198 is a critical flaw in the Cisco IOS XE web UI that lets an unauthenticated remote attacker gain initial access and create a local priv…KEVEPSS 100%analysed9.8CVE-2018-0171Cisco IOS Smart Install improper input validation allows remote code executionCisco IOS and IOS XE Smart Install fails to properly validate packet data, so a crafted Smart Install message sent to TCP port 4786 can overflow a bu…KEVEPSS 99%analysed9.8CVE-2018-0151Cisco IOS/IOS XE QoS UDP Port 18999 Buffer OverflowCisco IOS and IOS XE contain a buffer overflow in the QoS subsystem caused by incorrect bounds checking of values in packets sent to UDP port 18999. …KEVEPSS 14%analysed9.8CVE-2017-12240Cisco IOS and IOS XE DHCP Relay Buffer Overflow RCEThe DHCP relay subsystem in Cisco IOS 12.2 through 15.6 and Cisco IOS XE contains a buffer overflow caused by improper input validation of DHCPv4 pac…KEVEPSS 14%analysed9.8CVE-2017-3881Cisco IOS/IOS XE CMP Telnet Option Handling RCECisco IOS and IOS XE fail to restrict CMP-specific Telnet options to internal cluster communications and mishandle malformed CMP Telnet options, so a…KEVEPSS 99%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.8CVE-2017-6736Cisco IOS and IOS XE SNMP buffer overflow remote code executionThe SNMP subsystem in Cisco IOS and IOS XE contains a buffer overflow that can be triggered by a crafted SNMP packet sent over IPv4 or IPv6. It affec…KEVEPSS 70%analysed8.8CVE-2017-6737Cisco IOS and IOS XE SNMP Buffer Overflow RCECisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMPv1, v2c, and v3. An authenticated remote attacker who know…KEVEPSS 45%analysed

Source: NIST National Vulnerability Database (record CVE-2018-0155), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.