Vulnerability record · CVE-2018-0171 · published 28 March 2018
CVE-2018-0171: Cisco IOS Smart Install improper input validation allows remote code execution
Cisco · Ios
Cisco IOS and IOS XE Smart Install fails to properly validate packet data, so a crafted Smart Install message sent to TCP port 4786 can overflow a buffer. The result is a device reload, an indefinite loop that triggers a watchdog crash, or arbitrary code execution. Because Smart Install is meant to simplify switch provisioning and is often left enabled and reachable, this is a serious exposure for network infrastructure.
Description
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute arbitrary code on an affected device. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted Smart Install message to an affected device on TCP port 4786. A successful exploit could allow the attacker to cause a buffer overflow on the affected device, which could have the following impacts: Triggering a reload of the device, Allowing the attacker to execute arbitrary code on the device, Causing an indefinite loop on the affected device that triggers a watchdog crash. Cisco Bug IDs: CSCvg76186.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, confirmed exploitation in CISA KEV, and near-maximum EPSS probability make this a top remediation priority.
What it is
Cisco IOS and IOS XE Smart Install fails to properly validate packet data, so a crafted Smart Install message sent to TCP port 4786 can overflow a buffer. The result is a device reload, an indefinite loop that triggers a watchdog crash, or arbitrary code execution. Because Smart Install is meant to simplify switch provisioning and is often left enabled and reachable, this is a serious exposure for network infrastructure.
Impact
An unauthenticated remote attacker can crash or reload the device, causing a denial of service, or execute arbitrary code with the privileges of the affected process, giving full control of the switch or router.
Attack surface
Reachable over the network via a crafted Smart Install message to TCP port 4786; the CVSS vector shows no privileges and no user interaction required. Any device with Smart Install enabled and port 4786 exposed is a candidate target.
Exploitation
Listed in CISA KEV since 2021-11-03 with a required action to apply vendor updates, and EPSS probability is 0.99479 (percentile 0.99943), indicating observed exploitation and very high likelihood of attempted exploitation. No ransomware campaign use is documented.
What to do
- Apply the Cisco updates referenced in the vendor advisory cisco-sa-20180328-smi2 as the primary fix.
- Disable the Smart Install feature on devices that do not require it, per Cisco guidance.
- Block or restrict TCP port 4786 at network boundaries and between network segments.
- Audit for Smart Install being enabled on internet-facing or untrusted-segment devices and remediate.
- Track CISA KEV remediation deadlines for any remaining affected devices.
Detection
- Monitor network traffic for connections to TCP port 4786, especially from unexpected or external sources.
- Alert on device reloads, watchdog crashes, or unexpected reboots of Cisco IOS/IOS XE devices.
- Review Cisco device logs for Smart Install activity and anomalous configuration changes.
- Use the Cisco advisory and ICS-CERT advisories to build inventory checks for affected IOS and IOS XE versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-0171 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-0171 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-0171), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.