PT-2018-1190 · Cisco · Cisco Ios+1

Published

2018-03-28

·

Updated

2025-10-28

·

CVE-2018-0154

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco Integrated Services Module for VPN (ISM-VPN) versions (affected versions not specified)
Description A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient handling of VPN traffic by the affected device. An attacker could exploit this vulnerability by sending crafted VPN traffic to an affected device. A successful exploit could allow the attacker to cause the affected device to hang or crash, resulting in a DoS condition.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Weakness Enumeration

Related Identifiers

BDU:2018-00648
CVE-2018-0154

Affected Products

Cisco Ios
Cisco Integrated Services Module For Vpn