Vulnerability record · CVE-2018-0172 · published 28 March 2018
CVE-2018-0172: Cisco IOS and IOS XE DHCP option 82 heap overflow denial of service
Cisco · Ios
Cisco IOS and IOS XE Software perform incomplete input validation of DHCP option 82 information received in DHCPv4 packets from relay agents. A crafted DHCPv4 packet triggers a heap overflow that causes the device to reload, producing a denial of service. Because the affected devices are network infrastructure, a successful hit removes forwarding and routing for everything behind them.
Description
A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software performs incomplete input validation of option 82 information that it receives in DHCP Version 4 (DHCPv4) packets from DHCP relay agents. An attacker could exploit this vulnerability by sending a crafted DHCPv4 packet to an affected device. A successful exploit could allow the attacker to cause a heap overflow condition on the affected device, which will cause the device to reload and result in a DoS condition. Cisco Bug IDs: CSCvg62730.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Automated analysis
high priorityThe flaw is remotely reachable without authentication or interaction, causes full device reload, and is listed in CISA KEV, though it is availability-only and requires DHCP option 82 traffic to reach the device.
What it is
Cisco IOS and IOS XE Software perform incomplete input validation of DHCP option 82 information received in DHCPv4 packets from relay agents. A crafted DHCPv4 packet triggers a heap overflow that causes the device to reload, producing a denial of service. Because the affected devices are network infrastructure, a successful hit removes forwarding and routing for everything behind them.
Impact
An unauthenticated, remote attacker can crash and reload an affected device, causing a denial of service. The CVSS vector shows no confidentiality or integrity impact, only availability loss, with scope change because the failure affects resources beyond the vulnerable component.
Attack surface
The flaw is reached over the network by sending a crafted DHCPv4 packet containing option 82 data to an affected device; the CVSS vector is AV:N/AC:L/PR:N/UI:N, so no authentication and no user interaction are required. The description states the option 82 information is expected from DHCP relay agents, so exposure depends on the device accepting such traffic.
Exploitation
CVE-2018-0172 is listed in CISA KEV with a due date of 2022-03-17, indicating known exploitation, and EPSS shows a 30-day probability of 0.0782 (94th percentile). No ransomware campaign use is documented in the record.
What to do
- Apply the Cisco updates referenced in the vendor advisory cisco-sa-20180328-dhcpr1, treating this as the primary action given KEV listing.
- If patching cannot be done immediately, restrict or filter DHCPv4 traffic carrying option 82 so only trusted relay agents can reach affected devices.
- Segment management and relay paths so untrusted hosts cannot inject DHCPv4 packets toward IOS/IOS XE devices.
- Track the device against the Cisco advisory and CISA KEV required action until the update is confirmed installed.
Detection
- Monitor device logs and syslog for unexpected reloads or crash traces on IOS/IOS XE devices that handle DHCP relay traffic.
- Alert on DHCPv4 packets containing option 82 arriving from sources other than known relay agents.
- Baseline normal DHCP relay traffic and flag option 82 payloads with anomalous length or content.
- Correlate device reload events with nearby DHCP traffic to distinguish this crash from other causes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-0172 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS and IOS XE Software Improper Input Validation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 March 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-0172 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-0172), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.