Vulnerability record · CVE-2018-0156 · published 28 March 2018
CVE-2018-0156: Cisco IOS Smart Install packet validation flaw causes device reload
Cisco · Ios
Cisco IOS and IOS XE Smart Install client switches fail to properly validate packet data received on TCP port 4786. An unauthenticated remote attacker can send a crafted packet that triggers a reload of the affected device, causing a denial of service. Only Smart Install client switches are affected; director-configured devices are not.
Description
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted packet to an affected device on TCP port 4786. Only Smart Install client switches are affected. Cisco devices that are configured as a Smart Install director are not affected by this vulnerability. Cisco Bug IDs: CSCvd40673.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityThe flaw is remotely exploitable without authentication, causes a full device reload, and is listed in CISA KEV as exploited in the wild, though impact is limited to availability.
What it is
Cisco IOS and IOS XE Smart Install client switches fail to properly validate packet data received on TCP port 4786. An unauthenticated remote attacker can send a crafted packet that triggers a reload of the affected device, causing a denial of service. Only Smart Install client switches are affected; director-configured devices are not.
Impact
The attacker can force an affected switch to reload, disrupting network availability for the duration of the outage. There is no confidentiality or integrity impact; the effect is purely denial of service.
Attack surface
Reachable over the network via TCP port 4786 with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Only devices acting as Smart Install clients are exposed.
Exploitation
CVE-2018-0156 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating exploitation in the wild. EPSS gives a 30-day probability of 0.08599 (94.8th percentile), and no ransomware campaign use is documented.
What to do
- Apply the Cisco updates referenced in the vendor advisory cisco-sa-20180328-smi; this is the required KEV action.
- If Smart Install is not needed, disable it on client switches.
- Block or restrict TCP port 4786 at network boundaries so only trusted management hosts can reach Smart Install clients.
- Identify any remaining Smart Install client switches and confirm none are director-configured, since directors are not affected.
- Track remediation against the CISA KEV due date of 2022-03-17 for any still-unpatched devices.
Detection
- Monitor for unexpected inbound connections or traffic to TCP port 4786 on Smart Install client switches.
- Alert on device reload or unexpected restart events on Cisco IOS/IOS XE switches and correlate with port 4786 activity.
- Review network telemetry for crafted or malformed packets directed at Smart Install clients from untrusted sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-0156 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 March 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-0156 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-0156), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.