CVE-2018-0175

Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCvd73664.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8 HIGH
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
ciscoCNA
---
---
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
VendorProductVersion
ciscoios
15.4\(3\)m4.1
ciscoios_xe
15.4\(3\)m4.1
ciscoios_xr
15.4\(3\)m4.1
ciscoios
𝑥
≤ 15.2\(4a\)ea5
ciscoios_xe
𝑥
≤ 15.2\(4a\)ea5
ciscoios
𝑥
≤ 15.2\(6\)e0a
ciscoios_xe
𝑥
≤ 15.2\(6\)e0a
ciscoios
𝑥
≤ 15.6.3m1
ciscoios_xe
𝑥
≤ 15.6.3m1
𝑥
= Vulnerable software versions