Vulnerability record · CVE-2018-0175 · published 28 March 2018
CVE-2018-0175: Cisco IOS, IOS XE and IOS XR LLDP format string flaw
Cisco · Ios
A format string vulnerability exists in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticated, adjacent attacker can trigger it to cause a denial of service or execute arbitrary code with elevated privileges on the affected device. Because LLDP is a link-layer protocol reachable from the local segment, any device on the same broadcast domain is a potential source.
Description
Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCvd73664.
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows unauthenticated adjacent code execution or DoS and is confirmed exploited in CISA KEV, though it requires adjacency and user interaction.
What it is
A format string vulnerability exists in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticated, adjacent attacker can trigger it to cause a denial of service or execute arbitrary code with elevated privileges on the affected device. Because LLDP is a link-layer protocol reachable from the local segment, any device on the same broadcast domain is a potential source.
Impact
Successful exploitation can crash or destabilize the device (denial of service) or allow arbitrary code execution with elevated privileges, giving the attacker control of the network device.
Attack surface
Reached over the adjacent network via LLDP frames; the CVSS vector shows AV:A with PR:N, so no authentication is required, but UI:R indicates some form of user interaction is needed. No remote or internet-facing path is described.
Exploitation
CVE-2018-0175 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), confirming real-world exploitation; EPSS 30-day probability is about 3.5% (88th percentile). No ransomware campaign use is documented.
What to do
- Apply the Cisco vendor updates referenced in the Cisco security advisory cisco-sa-20180328-lldp.
- If LLDP is not required, disable it on affected interfaces to remove the attack surface.
- Restrict Layer 2 adjacency on LLDP-enabled segments and disable LLDP on untrusted edge ports.
- Monitor CISA KEV guidance and apply the required action per vendor instructions within the stated due date.
- Segment management and access networks so untrusted hosts cannot reach LLDP-enabled device interfaces.
Detection
- Alert on malformed or unusually long LLDP TLVs observed on switch and router interfaces.
- Monitor device logs and crash dumps for LLDP subsystem faults or unexpected reloads.
- Baseline LLDP neighbor tables and flag unexpected or spoofed LLDP neighbors on access ports.
- Watch for interface flaps or device restarts correlated with LLDP traffic on adjacent segments.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-0175 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 March 2022.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-0175 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-0175), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.