← Vulnerability feed

Vulnerability record · CVE-2018-0167 · published 28 March 2018

CVE-2018-0167: Cisco IOS, IOS XE and IOS XR LLDP buffer overflow

Cisco · Ios

Multiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticated attacker on the same Layer 2 segment can trigger memory corruption, causing a denial of service or potentially code execution with elevated privileges. The record does not list specific affected releases or fixed versions, so those must be confirmed against the Cisco advisory.

8.8 CVSS 3.1 High CISA KEV since 3 Mar 2022 EPSS 3.4% · top 11.7% CWE-119 · Memory buffer overflow
8.8CVSS 3.1 base score, v2 8.3
3.4%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
13References
17 Jun 2026Last modified by NVD

Description

Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCuo17183, CSCvd73487.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is remotely triggerable without authentication from an adjacent network, rated CVSS 8.8, and is in CISA's KEV catalog, though exploitation requires Layer 2 adjacency and no public exploit detail is given in the record.

What it is

Multiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticated attacker on the same Layer 2 segment can trigger memory corruption, causing a denial of service or potentially code execution with elevated privileges. The record does not list specific affected releases or fixed versions, so those must be confirmed against the Cisco advisory.

Impact

An attacker gains the ability to crash or reload the affected device, and in the worst case execute arbitrary code with elevated privileges on it. Because the flaw sits in a network infrastructure component, a successful exploit can disrupt or take over routing and switching functions.

Attack surface

Reachable over the adjacent network via LLDP frames, per the CVSS vector AV:A/AC:L/PR:N/UI:N, so no authentication and no user interaction are required. The attacker only needs Layer 2 adjacency to a device running a vulnerable LLDP implementation.

Exploitation

The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, indicating real-world exploitation, though the record does not document ransomware use. EPSS gives a 30-day exploitation probability of about 3.4 percent (88th percentile), and no reference is tagged as an exploit or proof-of-concept.

What to do

  • Apply the Cisco IOS, IOS XE and IOS XR updates referenced in Cisco advisory cisco-sa-20180328-lldp, prioritizing internet- and edge-facing devices.
  • If LLDP is not required, disable it on affected interfaces to remove the attack surface.
  • Restrict Layer 2 adjacency on access ports (port security, 802.1X, disabling unused ports) to limit who can send LLDP frames.
  • Segment management and access networks so untrusted hosts cannot reach LLDP-speaking infrastructure directly.
  • Track CISA KEV remediation due dates and verify patched versions after upgrade.

Detection

  • Monitor device logs and syslog for unexpected reloads, crashes or LLDP-related tracebacks on Cisco IOS, IOS XE and IOS XR devices.
  • Watch for LLDP frames with malformed or oversized TLVs on access and inter-switch links using switch or IDS/IPS telemetry.
  • Alert on new or unexpected LLDP neighbors appearing on access ports, which may indicate an attacker on the segment.
  • Correlate device uptime resets and interface flaps with LLDP traffic bursts to spot exploitation attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-0167 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 March 2022.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-0167 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2023-20198Cisco IOS XE Web UI unauthenticated privilege escalation and implant deploymentCVE-2023-20198 is a critical flaw in the Cisco IOS XE web UI that lets an unauthenticated remote attacker gain initial access and create a local priv…KEVEPSS 100%analysed9.8CVE-2018-0171Cisco IOS Smart Install improper input validation allows remote code executionCisco IOS and IOS XE Smart Install fails to properly validate packet data, so a crafted Smart Install message sent to TCP port 4786 can overflow a bu…KEVEPSS 99%analysed9.8CVE-2018-0151Cisco IOS/IOS XE QoS UDP Port 18999 Buffer OverflowCisco IOS and IOS XE contain a buffer overflow in the QoS subsystem caused by incorrect bounds checking of values in packets sent to UDP port 18999. …KEVEPSS 14%analysed9.8CVE-2017-12240Cisco IOS and IOS XE DHCP Relay Buffer Overflow RCEThe DHCP relay subsystem in Cisco IOS 12.2 through 15.6 and Cisco IOS XE contains a buffer overflow caused by improper input validation of DHCPv4 pac…KEVEPSS 14%analysed9.8CVE-2017-3881Cisco IOS/IOS XE CMP Telnet Option Handling RCECisco IOS and IOS XE fail to restrict CMP-specific Telnet options to internal cluster communications and mishandle malformed CMP Telnet options, so a…KEVEPSS 99%analysed8.8CVE-2020-3118Cisco IOS XR CDP packet parsing flaw allows adjacent code executionCisco IOS XR's Cisco Discovery Protocol implementation fails to properly validate string input in certain CDP message fields, allowing a stack overfl…KEVEPSS 12%analysed8.8CVE-2017-6736Cisco IOS and IOS XE SNMP buffer overflow remote code executionThe SNMP subsystem in Cisco IOS and IOS XE contains a buffer overflow that can be triggered by a crafted SNMP packet sent over IPv4 or IPv6. It affec…KEVEPSS 70%analysed8.8CVE-2017-6737Cisco IOS and IOS XE SNMP Buffer Overflow RCECisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMPv1, v2c, and v3. An authenticated remote attacker who know…KEVEPSS 45%analysed

Source: NIST National Vulnerability Database (record CVE-2018-0167), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.