Vulnerability record · CVE-2018-0159 · published 28 March 2018
CVE-2018-0159: Cisco IOS and IOS XE IKEv1 packet validation flaw causes reload DoS
Cisco · Ios
Cisco IOS and IOS XE fail to properly validate specific IKEv1 packets during negotiation, letting a remote unauthenticated attacker crash the device. Because IKE is commonly exposed on internet-facing VPN gateways, a single crafted packet can take down routing and VPN services.
Description
A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of specific IKEv1 packets. An attacker could exploit this vulnerability by sending crafted IKEv1 packets to an affected device during an IKE negotiation. A successful exploit could allow the attacker to cause an affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCuj73916.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityRemote unauthenticated availability impact on internet-facing VPN gateways plus confirmed KEV exploitation status raises this above routine patching.
What it is
Cisco IOS and IOS XE fail to properly validate specific IKEv1 packets during negotiation, letting a remote unauthenticated attacker crash the device. Because IKE is commonly exposed on internet-facing VPN gateways, a single crafted packet can take down routing and VPN services.
Impact
An attacker can force an affected device to reload, causing a denial of service that disrupts all traffic and VPN sessions handled by that device. No data confidentiality or integrity loss is described; the effect is availability only.
Attack surface
Reachable over the network via crafted IKEv1 packets sent during an IKE negotiation, with no authentication or user interaction required (CVSS AV:N/PR:N/UI:N). Any device with IKEv1 enabled and reachable on UDP 500/4500 is exposed.
Exploitation
CVE-2018-0159 is listed in CISA KEV (added 2022-03-03), indicating known exploitation, and EPSS shows a 30-day probability of roughly 6.9 percent (93.7th percentile). References are vendor advisory and government catalog entries; no public exploit code is cited in the record.
What to do
- Apply the Cisco IOS/IOS XE updates referenced in Cisco advisory cisco-sa-20180328-ike-dos.
- If IKEv1 is not required, disable it or migrate to IKEv2 on affected devices.
- Restrict UDP 500/4500 access to known peer IPs with ACLs or infrastructure firewalls.
- Monitor Cisco bug CSCuj73916 and the KEV entry for updated guidance and due dates.
Detection
- Alert on unexpected device reloads or crash/restart syslog events on IKE-enabled IOS/IOS XE devices.
- Monitor IKE negotiation logs for malformed or anomalous IKEv1 packets and repeated negotiation failures.
- Track SNMP or syslog uptime resets on VPN gateways and correlate with inbound UDP 500/4500 traffic spikes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-0159 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 March 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/103562 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040595 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-ike-dos | Vendor Advisory |
| http://www.securityfocus.com/bid/103562 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040595 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-ike-dos | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-0159 | US Government Resource |
Track CVE-2018-0159 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-0159), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.