← Vulnerability feed

Vulnerability record · CVE-2018-0171 · published 28 March 2018

CVE-2018-0171: Cisco IOS Smart Install improper input validation allows remote code execution

Cisco · Ios

Cisco IOS and IOS XE Smart Install fails to properly validate packet data, so a crafted Smart Install message sent to TCP port 4786 can overflow a buffer. The result is a device reload, an indefinite loop that triggers a watchdog crash, or arbitrary code execution. Because Smart Install is meant to simplify switch provisioning and is often left enabled and reachable, this is a serious exposure for network infrastructure.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 EPSS 99% · top 0.1% CWE-20 · Improper input validationCWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score, v2 10.0
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
13References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute arbitrary code on an affected device. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted Smart Install message to an affected device on TCP port 4786. A successful exploit could allow the attacker to cause a buffer overflow on the affected device, which could have the following impacts: Triggering a reload of the device, Allowing the attacker to execute arbitrary code on the device, Causing an indefinite loop on the affected device that triggers a watchdog crash. Cisco Bug IDs: CSCvg76186.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required, confirmed exploitation in CISA KEV, and near-maximum EPSS probability make this a top remediation priority.

What it is

Cisco IOS and IOS XE Smart Install fails to properly validate packet data, so a crafted Smart Install message sent to TCP port 4786 can overflow a buffer. The result is a device reload, an indefinite loop that triggers a watchdog crash, or arbitrary code execution. Because Smart Install is meant to simplify switch provisioning and is often left enabled and reachable, this is a serious exposure for network infrastructure.

Impact

An unauthenticated remote attacker can crash or reload the device, causing a denial of service, or execute arbitrary code with the privileges of the affected process, giving full control of the switch or router.

Attack surface

Reachable over the network via a crafted Smart Install message to TCP port 4786; the CVSS vector shows no privileges and no user interaction required. Any device with Smart Install enabled and port 4786 exposed is a candidate target.

Exploitation

Listed in CISA KEV since 2021-11-03 with a required action to apply vendor updates, and EPSS probability is 0.99479 (percentile 0.99943), indicating observed exploitation and very high likelihood of attempted exploitation. No ransomware campaign use is documented.

What to do

  • Apply the Cisco updates referenced in the vendor advisory cisco-sa-20180328-smi2 as the primary fix.
  • Disable the Smart Install feature on devices that do not require it, per Cisco guidance.
  • Block or restrict TCP port 4786 at network boundaries and between network segments.
  • Audit for Smart Install being enabled on internet-facing or untrusted-segment devices and remediate.
  • Track CISA KEV remediation deadlines for any remaining affected devices.

Detection

  • Monitor network traffic for connections to TCP port 4786, especially from unexpected or external sources.
  • Alert on device reloads, watchdog crashes, or unexpected reboots of Cisco IOS/IOS XE devices.
  • Review Cisco device logs for Smart Install activity and anomalous configuration changes.
  • Use the Cisco advisory and ICS-CERT advisories to build inventory checks for affected IOS and IOS XE versions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-0171 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-0171 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-12240Cisco IOS and IOS XE DHCP Relay Buffer Overflow RCEThe DHCP relay subsystem in Cisco IOS 12.2 through 15.6 and Cisco IOS XE contains a buffer overflow caused by improper input validation of DHCPv4 pac…KEVEPSS 14%analysed9.8CVE-2017-3881Cisco IOS/IOS XE CMP Telnet Option Handling RCECisco IOS and IOS XE fail to restrict CMP-specific Telnet options to internal cluster communications and mishandle malformed CMP Telnet options, so a…KEVEPSS 99%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.8CVE-2017-6736Cisco IOS and IOS XE SNMP buffer overflow remote code executionThe SNMP subsystem in Cisco IOS and IOS XE contains a buffer overflow that can be triggered by a crafted SNMP packet sent over IPv4 or IPv6. It affec…KEVEPSS 70%analysed8.8CVE-2017-6737Cisco IOS and IOS XE SNMP Buffer Overflow RCECisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMPv1, v2c, and v3. An authenticated remote attacker who know…KEVEPSS 45%analysed8.8CVE-2017-6738Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionThe SNMP subsystem in Cisco IOS and IOS XE Software contains a buffer overflow that affects SNMP versions 1, 2c, and 3. An authenticated remote attac…KEVEPSS 11%analysed8.8CVE-2017-6739Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionCisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMP versions 1, 2c, and 3. A remote attacker who knows the SN…KEVEPSS 11%analysed8.8CVE-2017-6740Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionCisco IOS and IOS XE contain a buffer overflow in the SNMP subsystem affecting SNMP versions 1, 2c, and 3. An authenticated remote attacker can send …KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-2018-0171), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.