Vulnerability record · CVE-2018-0167 · published 28 March 2018
CVE-2018-0167: Cisco IOS, IOS XE and IOS XR LLDP buffer overflow
Cisco · Ios
Multiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticated attacker on the same Layer 2 segment can trigger memory corruption, causing a denial of service or potentially code execution with elevated privileges. The record does not list specific affected releases or fixed versions, so those must be confirmed against the Cisco advisory.
Description
Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCuo17183, CSCvd73487.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is remotely triggerable without authentication from an adjacent network, rated CVSS 8.8, and is in CISA's KEV catalog, though exploitation requires Layer 2 adjacency and no public exploit detail is given in the record.
What it is
Multiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticated attacker on the same Layer 2 segment can trigger memory corruption, causing a denial of service or potentially code execution with elevated privileges. The record does not list specific affected releases or fixed versions, so those must be confirmed against the Cisco advisory.
Impact
An attacker gains the ability to crash or reload the affected device, and in the worst case execute arbitrary code with elevated privileges on it. Because the flaw sits in a network infrastructure component, a successful exploit can disrupt or take over routing and switching functions.
Attack surface
Reachable over the adjacent network via LLDP frames, per the CVSS vector AV:A/AC:L/PR:N/UI:N, so no authentication and no user interaction are required. The attacker only needs Layer 2 adjacency to a device running a vulnerable LLDP implementation.
Exploitation
The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, indicating real-world exploitation, though the record does not document ransomware use. EPSS gives a 30-day exploitation probability of about 3.4 percent (88th percentile), and no reference is tagged as an exploit or proof-of-concept.
What to do
- Apply the Cisco IOS, IOS XE and IOS XR updates referenced in Cisco advisory cisco-sa-20180328-lldp, prioritizing internet- and edge-facing devices.
- If LLDP is not required, disable it on affected interfaces to remove the attack surface.
- Restrict Layer 2 adjacency on access ports (port security, 802.1X, disabling unused ports) to limit who can send LLDP frames.
- Segment management and access networks so untrusted hosts cannot reach LLDP-speaking infrastructure directly.
- Track CISA KEV remediation due dates and verify patched versions after upgrade.
Detection
- Monitor device logs and syslog for unexpected reloads, crashes or LLDP-related tracebacks on Cisco IOS, IOS XE and IOS XR devices.
- Watch for LLDP frames with malformed or oversized TLVs on access and inter-switch links using switch or IDS/IPS telemetry.
- Alert on new or unexpected LLDP neighbors appearing on access ports, which may indicate an attacker on the segment.
- Correlate device uptime resets and interface flaps with LLDP traffic bursts to spot exploitation attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-0167 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 March 2022.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-0167 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-0167), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.