A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial of service (DoS) condition. The vulnerability is due to insufficient error handling when the BFD header in a BFD packet is incomplete. An attacker could exploit this vulnerability by sending a crafted BFD message to or across an affected switch. A successful exploit could allow the attacker to trigger a reload of the system. This vulnerability affects Catalyst 4500 Supervisor Engine 6-E (K5), Catalyst 4500 Supervisor Engine 6L-E (K10), Catalyst 4500 Supervisor Engine 7-E (K10), Catalyst 4500 Supervisor Engine 7L-E (K10), Catalyst 4500E Supervisor Engine 8-E (K10), Catalyst 4500E Supervisor Engine 8L-E (K10), Catalyst 4500E Supervisor Engine 9-E (K10), Catalyst 4500-X Series Switches (K10), Catalyst 4900M Switch (K5), Catalyst 4948E Ethernet Switch (K5). Cisco Bug IDs: CSCvc40729.

Project Subscriptions

Vendors Products
Catalyst 4500-x Series Switches \(k10\) Subscribe
Catalyst 4500 Supervisor Engine 6-e \(k5\) Subscribe
Catalyst 4500 Supervisor Engine 6l-e \(k10\) Subscribe
Catalyst 4500 Supervisor Engine 7-e \(k10\) Subscribe
Catalyst 4500 Supervisor Engine 7l-e \(k10\) Subscribe
Catalyst 4500e Supervisor Engine 8-e \(k10\) Subscribe
Catalyst 4500e Supervisor Engine 8l-e \(k10\) Subscribe
Catalyst 4500e Supervisor Engine 9-e \(k10\) Subscribe
Catalyst 4900m Switch \(k5\) Subscribe
Catalyst 4948e Ethernet Switch \(k5\) Subscribe
Rockwellautomation Subscribe
Allen-bradley Stratix 8300 Industrial Managed Ethernet Switch Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 22 Oct 2025 00:15:00 +0000


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000


Fri, 15 Nov 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2022-03-03'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-01-12T21:52:53.398Z

Reserved: 2017-11-27T00:00:00.000Z

Link: CVE-2018-0155

cve-icon Vulnrichment

Updated: 2024-08-05T03:14:16.886Z

cve-icon NVD

Status : Analyzed

Published: 2018-03-28T22:29:00.420

Modified: 2026-01-13T22:22:09.993

Link: CVE-2018-0155

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses