CVE Feed

    Dashboard / CVE / CVE-2018-0161

    CVE-2018-0161

    A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial of service (DoS) condition, aka a GET MIB Object ID Denial of Service Vulnerability. The vulnerability is due to a condition that could occur when the affected software processes an SNMP read request that contains a request for the ciscoFlashMIB object ID (OID). An attacker could trigger this vulnerability by issuing an SNMP GET request for the ciscoFlashMIB OID on an affected device. A successful exploit could cause the affected device to restart due to a SYS-3-CPUHOG. This vulnerability affects the following Cisco devices if they are running a vulnerable release of Cisco IOS Software and are configured to use SNMP Version 2 (SNMPv2) or SNMP Version 3 (SNMPv3): Cisco Catalyst 2960-L Series Switches, Cisco Catalyst Digital Building Series Switches 8P, Cisco Catalyst Digital Building Series Switches 8U. Cisco Bug IDs: CSCvd89541.

    Published:Mar 28, 2018
    Last Modified:Jan 14, 2026
    EPS:Mar 28, 2018
    EPSS Score:0.01658
    CVSS Score:6.3

    CISA Notification

    Description

    A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial of service (DoS) condition, aka a GET MIB Object ID Denial of Service Vulnerability. The vulnerability is due to a condition that could occur when the affected software processes an SNMP read request that contains a request for the ciscoFlashMIB object ID (OID). An attacker could trigger this vulnerability by issuing an SNMP GET request for the ciscoFlashMIB OID on an affected device. A successful exploit could cause the affected device to restart due to a SYS-3-CPUHOG. This vulnerability affects the following Cisco devices if they are running a vulnerable release of Cisco IOS Software and are configured to use SNMP Version 2 (SNMPv2) or SNMP Version 3 (SNMPv3): Cisco Catalyst 2960-L Series Switches, Cisco Catalyst Digital Building Series Switches 8P, Cisco Catalyst Digital Building Series Switches 8U. Cisco Bug IDs: CSCvd89541.

    Required Action:

    Apply updates per vendor instructions.

    Notes:

    No extra notes provided.

    Due Date
    Mar 17, 2022
    1639 days ago
    Alert Date
    Mar 3, 2022
    1653 days ago

    Affected Products

    Vendor
    Cisco
    Product
    Catalyst 2960l-16ps-ll
    Vendor
    Cisco
    Product
    Catalyst 2960l-16ts-ll
    Vendor
    Cisco
    Product
    Catalyst 2960l-24pq-ll
    Vendor
    Cisco
    Product
    Catalyst 2960l-24ps-ll
    Vendor
    Cisco
    Product
    Catalyst 2960l-24tq-ll
    Vendor
    Cisco
    Product
    Catalyst 2960l-24ts-ll
    Vendor
    Cisco
    Product
    Catalyst 2960l-48pq-ll
    Vendor
    Cisco
    Product
    Catalyst 2960l-48ps-ll
    Vendor
    Cisco
    Product
    Catalyst 2960l-48tq-ll
    Vendor
    Cisco
    Product
    Catalyst 2960l-48ts-ll
    Vendor
    Cisco
    Product
    Catalyst 2960l-8ps-ll
    Vendor
    Cisco
    Product
    Catalyst 2960l-8ts-ll
    Vendor
    Cisco
    Product
    Catalyst Digital Building Series Switches-8p
    Vendor
    Cisco
    Product
    Catalyst Digital Building Series Switches-8u
    Vendor
    Cisco
    Product
    Ios

    Exploits

    No exploit reference

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High