Vulnerability record · CVE-2018-0180 · published 28 March 2018
CVE-2018-0180: Cisco IOS Login Block feature denial-of-service via crafted login attempts
Cisco · Ios
Multiple flaws in the Login Enhancements (Login Block) feature of Cisco IOS Software let an unauthenticated remote attacker trigger a reload of the device, causing a denial of service. The issue affects devices running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Because it can take down core network devices without credentials, it is a serious availability risk for organizations running those releases.
Description
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Cisco Bug IDs: CSCuy32360, CSCuz60599.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityThe flaw is remotely triggerable without authentication and is listed in CISA KEV as exploited, though it only causes denial of service and has high attack complexity.
What it is
Multiple flaws in the Login Enhancements (Login Block) feature of Cisco IOS Software let an unauthenticated remote attacker trigger a reload of the device, causing a denial of service. The issue affects devices running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Because it can take down core network devices without credentials, it is a serious availability risk for organizations running those releases.
Impact
An attacker can force an affected device to reload, interrupting routing, switching and any services that depend on it. No data is read or changed; the gain is purely denial of service against the network device.
Attack surface
The flaw is reachable over the network through the Login Block feature, which processes login attempts; the CVSS vector shows AV:N/PR:N/UI:N, so no authentication or user interaction is required. The high attack complexity (AC:H) indicates a narrow timing or condition window rather than a trivial trigger.
Exploitation
CVE-2018-0180 is listed in CISA KEV with a required action to apply vendor updates, indicating known exploitation in the wild. EPSS gives a 30-day probability of about 4.9 percent (91.7th percentile), and no ransomware campaign use is documented.
What to do
- Apply the Cisco IOS Software updates referenced in Cisco advisory cisco-sa-20180328-slogin for the affected 15.4(2)T, 15.4(3)M and 15.4(2)CG releases.
- If immediate patching is not possible, follow the vendor advisory's mitigation guidance for the Login Block feature, including disabling or tuning it where operationally acceptable.
- Restrict management and login access to trusted networks with ACLs and infrastructure access control lists so only authorized sources can reach device login services.
- Monitor Cisco security advisories and CISA KEV for updated guidance and confirm affected devices are inventoried and tracked to remediation.
- Maintain out-of-band management and tested configuration backups so a device reload can be recovered quickly.
Detection
- Alert on unexpected reloads or reboots of Cisco IOS devices, correlating them with bursts of failed login attempts or Login Block activity.
- Monitor syslog and SNMP traps for login-block, authentication-failure and reload/crash messages on affected IOS releases.
- Baseline normal login attempt volume per device and flag spikes from unexpected source addresses against management interfaces.
- Track device uptime resets and verify whether they coincide with external login traffic to distinguish this DoS from other causes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-0180 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS Software Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 March 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/103556 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-slogin | MitigationVendor Advisory |
| http://www.securityfocus.com/bid/103556 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-slogin | MitigationVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-0180 | US Government Resource |
Track CVE-2018-0180 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-0180), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.