Cisco IOS and IOS XE Software ... Note

Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability

Cisco is warning of continued exploitation of a critical vulnerability affecting Cisco IOS and IOS XE Software's Smart Install feature. This flaw allows unauthenticated remote attackers to cause denial of service or execute arbitrary code. The vulnerability stems from improper packet data validation, exploitable by sending crafted messages to TCP port 4786. A successful exploit can lead to buffer overflows, triggering device reloads, arbitrary code execution, or indefinite loops causing watchdog crashes. Cisco has released software updates to fix this issue, and no workarounds are available. The Smart Install client is enabled by default on unpatched switches. This advisory is part of a larger bundle of security advisories released in March 2018, addressing multiple vulnerabilities. The specific vulnerability is identified as CVE-2018-0171. Customers are strongly urged to assess their systems and upgrade to a fixed software release immediately.