Vulnerability record · CVE-2018-0161 · published 28 March 2018
CVE-2018-0161: Cisco IOS SNMP GET Request Causes Device Restart
Cisco · Ios
Cisco IOS Software on certain Catalyst switches mishandles SNMP read requests for the ciscoFlashMIB object ID, causing a SYS-3-CPUHOG condition that restarts the device. The flaw is remotely reachable by an authenticated SNMPv2 or SNMPv3 user and results in a denial of service. It matters because it can repeatedly take down switch availability in environments where SNMP is enabled.
Description
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial of service (DoS) condition, aka a GET MIB Object ID Denial of Service Vulnerability. The vulnerability is due to a condition that could occur when the affected software processes an SNMP read request that contains a request for the ciscoFlashMIB object ID (OID). An attacker could trigger this vulnerability by issuing an SNMP GET request for the ciscoFlashMIB OID on an affected device. A successful exploit could cause the affected device to restart due to a SYS-3-CPUHOG. This vulnerability affects the following Cisco devices if they are running a vulnerable release of Cisco IOS Software and are configured to use SNMP Version 2 (SNMPv2) or SNMP Version 3 (SNMPv3): Cisco Catalyst 2960-L Series Switches, Cisco Catalyst Digital Building Series Switches 8P, Cisco Catalyst Digital Building Series Switches 8U. Cisco Bug IDs: CSCvd89541.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H
Automated analysis
high priorityThe flaw is remotely triggerable with valid SNMP credentials, causes full device restart, and is listed in CISA KEV, though it requires authentication and a specific OID request.
What it is
Cisco IOS Software on certain Catalyst switches mishandles SNMP read requests for the ciscoFlashMIB object ID, causing a SYS-3-CPUHOG condition that restarts the device. The flaw is remotely reachable by an authenticated SNMPv2 or SNMPv3 user and results in a denial of service. It matters because it can repeatedly take down switch availability in environments where SNMP is enabled.
Impact
An attacker with valid SNMP credentials can force the affected switch to restart, interrupting network access for everything behind it. No data is read or modified; the gain is purely availability loss.
Attack surface
Reached over the network via SNMPv2 or SNMPv3 on devices configured for SNMP. Authentication is required (a valid SNMP community or user), and no user interaction is needed.
Exploitation
CVE-2018-0161 is listed in CISA's Known Exploited Vulnerabilities catalog, indicating observed exploitation, though the record does not describe specific campaigns. EPSS gives a 30-day probability of about 4.1 percent (90th percentile).
What to do
- Apply the Cisco IOS Software updates referenced in the Cisco security advisory cisco-sa-20180328-snmp.
- If patching cannot be done immediately, disable SNMPv2 and SNMPv3 on affected Catalyst 2960-L and Digital Building switches, or restrict SNMP access to trusted management hosts via ACLs.
- Replace SNMPv2c community strings with SNMPv3 authenticated users and avoid read access to the ciscoFlashMIB OID where possible.
- Monitor for unexpected device restarts and correlate them with SNMP GET activity for the ciscoFlashMIB OID.
Detection
- Alert on SNMP GET requests targeting the ciscoFlashMIB OID from unexpected or non-management source addresses.
- Track SYS-3-CPUHOG syslog messages and unexpected reload events on Catalyst 2960-L and Digital Building switches.
- Baseline normal SNMP polling sources and flag new or high-volume SNMPv2/v3 querying hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-0161 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS Software Resource Management Errors Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 March 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/103573 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040589 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-snmp | MitigationVendor Advisory |
| http://www.securityfocus.com/bid/103573 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1040589 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-snmp | MitigationVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-0161 | US Government Resource |
Track CVE-2018-0161 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-0161), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.