Description
A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software performs incomplete input validation of option 82 information that it receives in DHCP Version 4 (DHCPv4) packets from DHCP relay agents. An attacker could exploit this vulnerability by sending a crafted DHCPv4 packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCuh91645.
Published: 2018-03-28
Score: 8.6 High
EPSS: 5.4% Low
KEV: Yes
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-0997 A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software performs incomplete input validation of option 82 information that it receives in DHCP Version 4 (DHCPv4) packets from DHCP relay agents. An attacker could exploit this vulnerability by sending a crafted DHCPv4 packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCuh91645.
History

Wed, 22 Oct 2025 00:15:00 +0000


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000


Wed, 13 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2022-03-03'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Cisco 7600 Series Route Switch Processor 720 7600 Series Supervisor Engine 32 7600 Series Supervisor Engine 720 Ios Ios Xe
Rockwellautomation Allen-bradley Armorstratix 5700 Allen-bradley Stratix 5400 Allen-bradley Stratix 5410 Allen-bradley Stratix 5700 Allen-bradley Stratix 8000 Allen-bradley Stratix 8300
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-01-12T22:01:10.567Z

Reserved: 2017-11-27T00:00:00.000Z

Link: CVE-2018-0174

cve-icon Vulnrichment

Updated: 2024-08-05T03:14:16.920Z

cve-icon NVD

Status : Analyzed

Published: 2018-03-28T22:29:01.233

Modified: 2026-01-14T18:46:04.390

Link: CVE-2018-0174

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses