← Global Threat Landscape

CVE-2018-0171

CWE-20

Critical

103.8

RPS

Description

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute arbitrary code on an affected device. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted Smart Install message to an affected device on TCP port 4786. A successful exploit could allow the attacker to cause a buffer overflow on the affected device, which could have the following impacts: Triggering a reload of the device, Allowing the attacker to execute arbitrary code on the device, Causing an indefinite loop on the affected device that triggers a watchdog crash. Cisco Bug IDs: CSCvg76186.

Source: NVD

Signals

CVSS
9.8
Critical · v3.1
EPSS
99.47%
Probability of exploitation in the next 30 days (FIRST)
CISA KEV
In CISA KEV since Nov 2021
Fix commit
No known fix commit
Sources: MoreFixes, FreshFixes
Weakness
CWE-20
CWE-20, CWE-787
Published
28 Mar 2018
Last modified 14 Jan 2026

How to read these signals: RPS · EPSS · CISA KEV · Data sources

Get this score from the API

curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
  https://api.intelligence.devsecure.io/api/v1/rps/CVE-2018-0171

Replace the placeholder with your key. Get a free API key or rank your own CVEs.

Data as of 8 Oct 2026, 05:16 UK time

CVE-2018-0171 · RPS 103.8 · DevSecure Intelligence