CVE-2018-0155
Cisco IOS / IOS XE · Switches, routers and SD-WAN
Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability
At a glance
Exploited. Added to CISA’s catalog of exploited vulnerabilities on March 3, 2022.
Affected product: Cisco IOS / IOS XE (category Switches, routers and SD-WAN, indicative classification). Name in CISA’s catalog: Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches.
What should I do?
Apply the security update from Cisco.
Deadline set by CISA for US federal agencies: 14 days (due March 17, 2022). It only binds those agencies, but it is a useful measure of urgency.
- Cisco security advisories page (general page, not the advisory for this vulnerability)
- The vendor’s specific advisory is listed in the NVD references: CVE-2018-0155 on the NVD website.
Original text of the required action (CISA)
Apply updates per vendor instructions.
Timeline
- Vulnerability published Publication date (NVD)
- Exploitation confirmed Added to CISA’s KEV catalog
- CISA deadline Remediation deadline set for US federal agencies
The facts, with their sources
- Exploitation confirmed
- Yes, on March 3, 2022 Date added to the catalog of exploited vulnerabilities. Exploitation itself may have started earlier. Source: KEV catalog, collected September 29, 2026 at 14:57 UTC
- Ransomware
- No known use to date That does not guarantee it is not being used: the information is not public. Source: KEV catalog, collected September 29, 2026 at 14:57 UTC
- Hunt for compromise
- Not requested by CISA Source: KEV catalog, collected September 29, 2026 at 14:57 UTC
- CISA required action
- Apply the security update from Cisco. Rewritten by this site from CISA’s original text. Source: KEV catalog, collected September 29, 2026 at 14:57 UTC
- CISA deadline
- March 17, 2022, 14 days Set for US federal agencies: a measure of urgency, not an obligation elsewhere. Source: KEV catalog, collected September 29, 2026 at 14:57 UTC
- Vulnerability published
- March 28, 2018 Source: National Vulnerability Database (NVD), collected September 29, 2026 at 15:00 UTC
- Product according to CISA
- Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches Filed by this site under “Switches, routers and SD-WAN” (indicative classification). Source: KEV catalog, collected September 29, 2026 at 14:57 UTC
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Technical detail of the score: attack vector, complexity, impact. Source: National Vulnerability Database (NVD), collected September 29, 2026 at 15:00 UTC
Severity and activity
FIRST’s EPSS model. Since exploitation is already confirmed, this figure is mostly useful to compare activity. Collected Sep 29, 2026.
Description
A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial of service (DoS) condition. The vulnerability is due to insufficient error handling when the BFD header in a BFD packet is incomplete. An attacker could exploit this vulnerability by sending a crafted BFD message to or across an affected switch. A successful exploit could allow the attacker to trigger a reload of the system. This vulnerability affects Catalyst 4500 Supervisor Engine 6-E (K5), Catalyst 4500 Supervisor Engine 6L-E (K10), Catalyst 4500 Supervisor Engine 7-E (K10), Catalyst 4500 Supervisor Engine 7L-E (K10), Catalyst 4500E Supervisor Engine 8-E (K10), Catalyst 4500E Supervisor Engine 8L-E (K10), Catalyst 4500E Supervisor Engine 9-E (K10), Catalyst 4500-X Series Switches (K10), Catalyst 4900M Switch (K5), Catalyst 4948E Ethernet Switch (K5). Cisco Bug IDs: CSCvc40729.
Official description from the NVD, collected Sep 29, 2026. CVE® description © The MITRE Corporation.
A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial-of-service (DoS) condition.
Summary from CISA (KEV catalog).
CERT-FR advisories
No advisory among the latest CERT-FR publications this site follows. That does not mean there are none.
Information reused under the Open Licence 2.0 (Etalab); the date of last update is shown for each advisory. This site is neither affiliated with nor endorsed by ANSSI.
Sources for this page
- CISA KEV catalog: exploitation, date added, required action, deadline, ransomware.
- NVD (NIST): CVSS severity, publication date, description, vendor references.
- EPSS (FIRST): probability of exploitation.
- CERT-FR: advisories and alerts (in French).
- Brand and category: indicative classification by this site (method).