← Vulnerability feed

Vulnerability record · CVE-2018-0161 · published 28 March 2018

CVE-2018-0161: Cisco IOS SNMP GET Request Causes Device Restart

Cisco · Ios

Cisco IOS Software on certain Catalyst switches mishandles SNMP read requests for the ciscoFlashMIB object ID, causing a SYS-3-CPUHOG condition that restarts the device. The flaw is remotely reachable by an authenticated SNMPv2 or SNMPv3 user and results in a denial of service. It matters because it can repeatedly take down switch availability in environments where SNMP is enabled.

6.3 CVSS 3.1 Medium CISA KEV since 3 Mar 2022 EPSS 4.1% · top 9.6% CWE-399 · CWE-399
6.3CVSS 3.1 base score, v2 6.3
4.1%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial of service (DoS) condition, aka a GET MIB Object ID Denial of Service Vulnerability. The vulnerability is due to a condition that could occur when the affected software processes an SNMP read request that contains a request for the ciscoFlashMIB object ID (OID). An attacker could trigger this vulnerability by issuing an SNMP GET request for the ciscoFlashMIB OID on an affected device. A successful exploit could cause the affected device to restart due to a SYS-3-CPUHOG. This vulnerability affects the following Cisco devices if they are running a vulnerable release of Cisco IOS Software and are configured to use SNMP Version 2 (SNMPv2) or SNMP Version 3 (SNMPv3): Cisco Catalyst 2960-L Series Switches, Cisco Catalyst Digital Building Series Switches 8P, Cisco Catalyst Digital Building Series Switches 8U. Cisco Bug IDs: CSCvd89541.

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw is remotely triggerable with valid SNMP credentials, causes full device restart, and is listed in CISA KEV, though it requires authentication and a specific OID request.

What it is

Cisco IOS Software on certain Catalyst switches mishandles SNMP read requests for the ciscoFlashMIB object ID, causing a SYS-3-CPUHOG condition that restarts the device. The flaw is remotely reachable by an authenticated SNMPv2 or SNMPv3 user and results in a denial of service. It matters because it can repeatedly take down switch availability in environments where SNMP is enabled.

Impact

An attacker with valid SNMP credentials can force the affected switch to restart, interrupting network access for everything behind it. No data is read or modified; the gain is purely availability loss.

Attack surface

Reached over the network via SNMPv2 or SNMPv3 on devices configured for SNMP. Authentication is required (a valid SNMP community or user), and no user interaction is needed.

Exploitation

CVE-2018-0161 is listed in CISA's Known Exploited Vulnerabilities catalog, indicating observed exploitation, though the record does not describe specific campaigns. EPSS gives a 30-day probability of about 4.1 percent (90th percentile).

What to do

  • Apply the Cisco IOS Software updates referenced in the Cisco security advisory cisco-sa-20180328-snmp.
  • If patching cannot be done immediately, disable SNMPv2 and SNMPv3 on affected Catalyst 2960-L and Digital Building switches, or restrict SNMP access to trusted management hosts via ACLs.
  • Replace SNMPv2c community strings with SNMPv3 authenticated users and avoid read access to the ciscoFlashMIB OID where possible.
  • Monitor for unexpected device restarts and correlate them with SNMP GET activity for the ciscoFlashMIB OID.

Detection

  • Alert on SNMP GET requests targeting the ciscoFlashMIB OID from unexpected or non-management source addresses.
  • Track SYS-3-CPUHOG syslog messages and unexpected reload events on Catalyst 2960-L and Digital Building switches.
  • Baseline normal SNMP polling sources and flag new or high-volume SNMPv2/v3 querying hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-0161 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS Software Resource Management Errors Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 March 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-0161 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-0171Cisco IOS Smart Install improper input validation allows remote code executionCisco IOS and IOS XE Smart Install fails to properly validate packet data, so a crafted Smart Install message sent to TCP port 4786 can overflow a bu…KEVEPSS 99%analysed9.8CVE-2017-12240Cisco IOS and IOS XE DHCP Relay Buffer Overflow RCEThe DHCP relay subsystem in Cisco IOS 12.2 through 15.6 and Cisco IOS XE contains a buffer overflow caused by improper input validation of DHCPv4 pac…KEVEPSS 14%analysed9.8CVE-2017-3881Cisco IOS/IOS XE CMP Telnet Option Handling RCECisco IOS and IOS XE fail to restrict CMP-specific Telnet options to internal cluster communications and mishandle malformed CMP Telnet options, so a…KEVEPSS 99%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.8CVE-2017-6736Cisco IOS and IOS XE SNMP buffer overflow remote code executionThe SNMP subsystem in Cisco IOS and IOS XE contains a buffer overflow that can be triggered by a crafted SNMP packet sent over IPv4 or IPv6. It affec…KEVEPSS 70%analysed8.8CVE-2017-6737Cisco IOS and IOS XE SNMP Buffer Overflow RCECisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMPv1, v2c, and v3. An authenticated remote attacker who know…KEVEPSS 45%analysed8.8CVE-2017-6738Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionThe SNMP subsystem in Cisco IOS and IOS XE Software contains a buffer overflow that affects SNMP versions 1, 2c, and 3. An authenticated remote attac…KEVEPSS 11%analysed8.8CVE-2017-6739Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionCisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMP versions 1, 2c, and 3. A remote attacker who knows the SN…KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-2018-0161), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.