Vulnerability record · CVE-2018-0155 · published 28 March 2018
CVE-2018-0155: Cisco Catalyst BFD offload incomplete header handling denial of service
Cisco · Ios
Cisco Catalyst 4500 and 4500-X series switches mishandle incomplete BFD headers in the BFD offload implementation, causing the iosd process to crash. An unauthenticated remote attacker can send a crafted BFD packet to or across an affected switch and force a system reload, disrupting all traffic through the device.
Description
A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial of service (DoS) condition. The vulnerability is due to insufficient error handling when the BFD header in a BFD packet is incomplete. An attacker could exploit this vulnerability by sending a crafted BFD message to or across an affected switch. A successful exploit could allow the attacker to trigger a reload of the system. This vulnerability affects Catalyst 4500 Supervisor Engine 6-E (K5), Catalyst 4500 Supervisor Engine 6L-E (K10), Catalyst 4500 Supervisor Engine 7-E (K10), Catalyst 4500 Supervisor Engine 7L-E (K10), Catalyst 4500E Supervisor Engine 8-E (K10), Catalyst 4500E Supervisor Engine 8L-E (K10), Catalyst 4500E Supervisor Engine 9-E (K10), Catalyst 4500-X Series Switches (K10), Catalyst 4900M Switch (K5), Catalyst 4948E Ethernet Switch (K5). Cisco Bug IDs: CSCvc40729.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Automated analysis
high priorityThe flaw is remotely exploitable without authentication, causes full device denial of service, and is listed in CISA KEV as exploited in the wild.
What it is
Cisco Catalyst 4500 and 4500-X series switches mishandle incomplete BFD headers in the BFD offload implementation, causing the iosd process to crash. An unauthenticated remote attacker can send a crafted BFD packet to or across an affected switch and force a system reload, disrupting all traffic through the device.
Impact
The attacker gains no code execution or data access; the outcome is a denial of service in which the switch reloads and forwarding is interrupted. Because the flaw is in the core iosd process, the whole device is affected rather than a single interface.
Attack surface
Reachable over the network via crafted BFD packets sent to or across the switch, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required, and the scope change (S:C) reflects impact beyond the vulnerable component.
Exploitation
CVE-2018-0155 is listed in CISA KEV with a 2022-03-03 addition date, indicating known exploitation in the wild, and EPSS shows a 30-day probability of 0.07742 (94th percentile). No ransomware campaign use is recorded.
What to do
- Apply the Cisco vendor advisory updates for the listed Catalyst 4500/4500-X supervisor engines and 4900/4948E switches.
- If BFD is not required, disable BFD offload or BFD on affected interfaces to remove the attack path.
- Restrict BFD traffic to trusted network segments with ACLs or infrastructure ACLs where operationally feasible.
- Monitor for unexpected switch reloads and treat repeated iosd crashes as a possible exploitation attempt.
Detection
- Alert on unexpected reloads or iosd process crashes on Catalyst 4500/4500-X platforms and correlate with BFD traffic.
- Inspect BFD packet captures for malformed or truncated BFD headers arriving from untrusted sources.
- Review syslog and SNMP traps for reload causes and BFD-related error messages around the time of a restart.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-0155 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 March 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/103565 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040587 | Third Party AdvisoryVDB Entry |
| https://ics-cert.us-cert.gov/advisories/ICSA-18-107-05 | Third Party AdvisoryUS Government Resource |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-bfd | Vendor Advisory |
| http://www.securityfocus.com/bid/103565 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040587 | Third Party AdvisoryVDB Entry |
| https://ics-cert.us-cert.gov/advisories/ICSA-18-107-05 | Third Party AdvisoryUS Government Resource |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-bfd | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-0155 | US Government Resource |
Track CVE-2018-0155 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-0155), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.