Vulnerability record · CVE-2018-0179 · published 28 March 2018
CVE-2018-0179: Cisco IOS Login Block feature denial-of-service flaw
Cisco · Ios
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software let an unauthenticated, remote attacker trigger a reload of an affected device, causing a denial-of-service condition. The flaw affects devices running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later, so internet-facing or management-reachable IOS devices are at risk of unexpected restarts.
Description
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Cisco Bug IDs: CSCuy32360, CSCuz60599.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityThe flaw is remotely triggerable without authentication and is confirmed exploited in CISA KEV, but it only causes availability loss and requires high attack complexity.
What it is
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software let an unauthenticated, remote attacker trigger a reload of an affected device, causing a denial-of-service condition. The flaw affects devices running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later, so internet-facing or management-reachable IOS devices are at risk of unexpected restarts.
Impact
An attacker can force an affected device to reload, disrupting routing, switching and any services the device provides until it recovers. There is no confidentiality or integrity impact; the effect is availability loss.
Attack surface
Reachable over the network (AV:N) with no authentication (PR:N) and no user interaction (UI:N), consistent with the Login Block feature being exercised remotely. The high attack complexity (AC:H) indicates a narrow or timing-dependent condition is needed to trigger the reload.
Exploitation
CVE-2018-0179 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), confirming real-world exploitation, though EPSS 30-day probability is low at roughly 4.9 percent. No ransomware campaign use is documented.
What to do
- Apply the Cisco IOS Software updates referenced in Cisco advisory cisco-sa-20180328-slogin; this is the required action under the CISA KEV entry.
- If immediate patching is not possible, disable or restrict the Login Enhancements (Login Block) feature where operationally feasible.
- Restrict management and login access to trusted networks with ACLs and infrastructure ACLs so only authorized sources can reach affected devices.
- Monitor Cisco advisories for updated fixed releases covering the affected 15.4(2)T, 15.4(3)M and 15.4(2)CG trains.
Detection
- Alert on unexpected device reloads or uptime resets on Cisco IOS devices running the affected releases.
- Correlate syslog messages around login-block or authentication events with subsequent reload or crash signatures.
- Baseline and monitor login attempts to management interfaces for anomalous patterns that could exercise the Login Block feature.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-0179 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS Software Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 March 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/103556 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-slogin | Vendor Advisory |
| http://www.securityfocus.com/bid/103556 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-slogin | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-0179 | US Government Resource |
Track CVE-2018-0179 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-0179), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.