← Vulnerability feed

Vulnerability record · CVE-2018-0158 · published 28 March 2018

CVE-2018-0158: Cisco IOS and IOS XE IKEv2 packet handling memory leak DoS

Cisco · Ios

Cisco IOS and IOS XE mishandle certain IKEv2 packets, causing improper input validation that leaks memory. Repeated crafted packets drive continuous memory consumption until the device reloads, producing a denial of service. The flaw is remotely reachable without authentication, so any internet-exposed IKEv2 endpoint is at risk.

8.6 CVSS 3.1 High CISA KEV since 3 Mar 2022 EPSS 7.2% · top 5.9% CWE-20 · Improper input validationCWE-401 · Memory leak
8.6CVSS 3.1 base score, v2 7.8
7.2%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
11References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain IKEv2 packets. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device to be processed. A successful exploit could cause an affected device to continuously consume memory and eventually reload, resulting in a DoS condition. Cisco Bug IDs: CSCvf22394.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityUnauthenticated remote denial of service with a CVSS of 8.6 and confirmed inclusion in CISA's KEV catalog, though no ransomware use is documented.

What it is

Cisco IOS and IOS XE mishandle certain IKEv2 packets, causing improper input validation that leaks memory. Repeated crafted packets drive continuous memory consumption until the device reloads, producing a denial of service. The flaw is remotely reachable without authentication, so any internet-exposed IKEv2 endpoint is at risk.

Impact

An unauthenticated remote attacker can exhaust device memory and force a reload, taking the affected router or switch offline. No data confidentiality or integrity loss is described; the gain is purely availability disruption.

Attack surface

Reached over the network via the IKEv2 service (UDP 500/4500) on affected devices; the CVSS vector shows no privileges and no user interaction required. Any device with IKEv2 enabled and reachable from untrusted networks is exposed.

Exploitation

CVE-2018-0158 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating real-world exploitation, and EPSS gives a 30-day probability of about 7.2 percent (94th percentile). No public exploit code or ransomware use is documented in this record.

What to do

  • Apply the Cisco IOS/IOS XE updates referenced in Cisco advisory cisco-sa-20180328-ike; this is the required KEV action.
  • If patching cannot be done immediately, restrict IKEv2 (UDP 500/4500) to trusted peers with ACLs or infrastructure access lists.
  • Disable IKEv2 on devices that do not need it.
  • Monitor device memory and reload events on IKEv2-enabled systems for signs of the leak.
  • Track the KEV due date (2022-03-17) and confirm remediation status for all affected devices.

Detection

  • Alert on sustained memory growth or unexpected reloads on IKEv2-enabled Cisco IOS/IOS XE devices.
  • Log and review IKEv2 packet rates and malformed IKEv2 traffic from untrusted sources.
  • Correlate device syslog reload or crash messages with IKEv2 activity in the preceding window.
  • Inventory IKEv2-exposed devices and verify they are patched against the Cisco advisory.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-0158 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 March 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/103566 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1040595 Broken LinkThird Party AdvisoryVDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-18-107-03 Third Party AdvisoryUS Government ResourceVDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-18-107-04 Third Party AdvisoryUS Government ResourceVDB Entry
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-ike Vendor Advisory
http://www.securityfocus.com/bid/103566 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1040595 Broken LinkThird Party AdvisoryVDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-18-107-03 Third Party AdvisoryUS Government ResourceVDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-18-107-04 Third Party AdvisoryUS Government ResourceVDB Entry
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-ike Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-0158 US Government Resource

Track CVE-2018-0158 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2023-20198Cisco IOS XE Web UI unauthenticated privilege escalation and implant deploymentCVE-2023-20198 is a critical flaw in the Cisco IOS XE web UI that lets an unauthenticated remote attacker gain initial access and create a local priv…KEVEPSS 100%analysed9.8CVE-2018-0171Cisco IOS Smart Install improper input validation allows remote code executionCisco IOS and IOS XE Smart Install fails to properly validate packet data, so a crafted Smart Install message sent to TCP port 4786 can overflow a bu…KEVEPSS 99%analysed9.8CVE-2018-0151Cisco IOS/IOS XE QoS UDP Port 18999 Buffer OverflowCisco IOS and IOS XE contain a buffer overflow in the QoS subsystem caused by incorrect bounds checking of values in packets sent to UDP port 18999. …KEVEPSS 14%analysed9.8CVE-2017-12240Cisco IOS and IOS XE DHCP Relay Buffer Overflow RCEThe DHCP relay subsystem in Cisco IOS 12.2 through 15.6 and Cisco IOS XE contains a buffer overflow caused by improper input validation of DHCPv4 pac…KEVEPSS 14%analysed9.8CVE-2017-3881Cisco IOS/IOS XE CMP Telnet Option Handling RCECisco IOS and IOS XE fail to restrict CMP-specific Telnet options to internal cluster communications and mishandle malformed CMP Telnet options, so a…KEVEPSS 99%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.8CVE-2017-6736Cisco IOS and IOS XE SNMP buffer overflow remote code executionThe SNMP subsystem in Cisco IOS and IOS XE contains a buffer overflow that can be triggered by a crafted SNMP packet sent over IPv4 or IPv6. It affec…KEVEPSS 70%analysed8.8CVE-2017-6737Cisco IOS and IOS XE SNMP Buffer Overflow RCECisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMPv1, v2c, and v3. An authenticated remote attacker who know…KEVEPSS 45%analysed

Source: NIST National Vulnerability Database (record CVE-2018-0158), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.