Vulnerability record · CVE-2018-0174 · published 28 March 2018
CVE-2018-0174: Cisco IOS and IOS XE DHCP option 82 input validation DoS
Cisco · Ios
Cisco IOS and IOS XE Software perform incomplete input validation of DHCP option 82 information received in DHCPv4 packets from relay agents. A crafted DHCPv4 packet can cause the affected device to reload, producing a denial of service. The flaw is remotely reachable without authentication, so any device processing such packets is exposed.
Description
A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software performs incomplete input validation of option 82 information that it receives in DHCP Version 4 (DHCPv4) packets from DHCP relay agents. An attacker could exploit this vulnerability by sending a crafted DHCPv4 packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCuh91645.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Automated analysis
high priorityThe flaw is remotely exploitable without authentication, causes full device reload, and is listed in CISA KEV as exploited in the wild.
What it is
Cisco IOS and IOS XE Software perform incomplete input validation of DHCP option 82 information received in DHCPv4 packets from relay agents. A crafted DHCPv4 packet can cause the affected device to reload, producing a denial of service. The flaw is remotely reachable without authentication, so any device processing such packets is exposed.
Impact
An attacker can force an affected device to reload, causing a denial of service. There is no reported confidentiality or integrity impact; the effect is availability loss on the device.
Attack surface
Reached over the network by sending a crafted DHCPv4 packet containing option 82 information to an affected device. The CVSS vector shows no privileges and no user interaction required, so it is unauthenticated and remote.
Exploitation
CVE-2018-0174 is listed in CISA's Known Exploited Vulnerabilities catalog, indicating known exploitation in the wild. EPSS gives a 30-day probability of about 7.6 percent (94th percentile), and references are vendor, CERT and third-party advisories rather than public exploit code.
What to do
- Apply the Cisco updates referenced in the vendor advisory cisco-sa-20180328-dhcpr3 as the primary fix.
- Follow CISA KEV required action to apply vendor updates within the stated remediation window.
- Restrict DHCP relay traffic and option 82 handling to trusted relay agents at network boundaries where feasible.
- Monitor affected IOS and IOS XE devices for unexpected reloads and correlate with DHCP traffic.
- Review exposure of management and relay-facing interfaces that accept DHCPv4 packets.
Detection
- Alert on unexpected device reloads or crash/restart events on Cisco IOS and IOS XE devices.
- Inspect DHCPv4 traffic for malformed or unusual option 82 content arriving from relay agents.
- Correlate spikes in DHCPv4 packets with device restart logs to identify attempted exploitation.
- Review syslog and SNMP traps for reload or watchdog events on affected platforms.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-0174 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 March 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-0174 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-0174), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.