Vulnerability record · CVE-2018-0173 · published 28 March 2018
CVE-2018-0173: Cisco IOS and IOS XE DHCPv4 Option 82 Input Validation DoS
Cisco · Ios
Cisco IOS and IOS XE software fails to properly validate encapsulated DHCP option 82 information in DHCPv4 packets, specifically in DHCPOFFER responses from servers. An unauthenticated remote attacker can send a crafted DHCPv4 packet that the device forwards to a DHCP server, and when the device processes the server's response, an error causes the device to reload. This results in a denial-of-service condition on the affected relay device.
Description
A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a Relay Reply denial of service (DoS) condition. The vulnerability exists because the affected software performs incomplete input validation of encapsulated option 82 information that it receives in DHCPOFFER messages from DHCPv4 servers. An attacker could exploit this vulnerability by sending a crafted DHCPv4 packet to an affected device, which the device would then forward to a DHCPv4 server. When the affected software processes the option 82 information that is encapsulated in the response from the server, an error could occur. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvg62754.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Automated analysis
high priorityThe vulnerability is remotely exploitable without authentication, has a high availability impact, and is listed in CISA KEV, though it only causes a denial of service.
What it is
Cisco IOS and IOS XE software fails to properly validate encapsulated DHCP option 82 information in DHCPv4 packets, specifically in DHCPOFFER responses from servers. An unauthenticated remote attacker can send a crafted DHCPv4 packet that the device forwards to a DHCP server, and when the device processes the server's response, an error causes the device to reload. This results in a denial-of-service condition on the affected relay device.
Impact
An attacker can cause the affected Cisco device to reload, disrupting network services and availability. The CVSS vector shows no confidentiality or integrity impact, only high availability impact.
Attack surface
The flaw is reachable over the network via DHCPv4 traffic; the CVSS vector indicates no privileges or user interaction are required. The attacker sends a crafted DHCPv4 packet that the device relays to a DHCPv4 server, and the device then processes the server's response.
Exploitation
CVE-2018-0173 is listed in CISA's Known Exploited Vulnerabilities catalog, indicating exploitation in the wild. EPSS estimates a 7.6% probability of exploitation in the next 30 days, placing it in the 94th percentile.
What to do
- Apply the updates specified in the Cisco security advisory cisco-sa-20180328-dhcpr2.
- If immediate patching is not possible, restrict DHCP relay traffic to trusted DHCP servers and networks.
- Disable DHCP option 82 insertion or relay on interfaces where it is not required.
- Monitor Cisco advisories and CISA KEV for updated guidance and patch status.
Detection
- Monitor device logs for unexpected reloads or crashes correlated with DHCP relay activity.
- Inspect DHCPv4 traffic for malformed or unusual option 82 encapsulated data in DHCPOFFER messages.
- Use network monitoring to detect spikes in DHCP relay traffic or repeated device restarts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-0173 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS and IOS XE Software Improper Input Validation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 March 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-0173 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-0173), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.