CVE-2018-0176
CVE-2018-0176 is a high-severity vulnerability in Cisco Ios Xe with a CVSS 3.x base score of 7.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-78.
Key facts
- Severity: High (CVSS 3.x base score 7.8)
- CVSS v2: 7.2
- EPSS exploit prediction: 0% (40th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-78
- Affected product: Cisco Ios Xe
- Published:
- Last modified:
Description
Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the device. The vulnerabilities are due to the affected software improperly sanitizing command arguments to prevent access to internal data structures on a device. An attacker who has user EXEC mode (privilege level 1) access to an affected device could exploit these vulnerabilities on the device by executing CLI commands that contain crafted arguments. A successful exploit could allow the attacker to gain access to the underlying Linux shell of the affected device and execute arbitrary commands with root privileges on the device. Cisco Bug IDs: CSCtw85441, CSCus42252, CSCuv95370.
Frequently asked questions
- What is CVE-2018-0176?
- Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the device. The vulnerabilities are due to the affected software improperly sanitizing command arguments to prevent access to internal data structures on a device. An attacker who has user EXEC mode (privilege level 1) access to an affected device could exploit these vulnerabilities on the device by executing CLI commands that contain crafted arguments. A successful exploit could allow the attacker to gain access to the underlying Linux shell of the affected device and execute arbitrary commands with root privileges on the device. Cisco Bug IDs: CSCtw85441, CSCus42252, CSCuv95370.
- How severe is CVE-2018-0176?
- CVE-2018-0176 has a CVSS 3.x base score of 7.8, rated high severity. It is exploitable over local access with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2018-0176 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (40th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2018-0176?
- CVE-2018-0176 primarily affects Cisco Ios Xe. In total, 3 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2018-0176?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2018-0176 published?
- CVE-2018-0176 was published on 2018-03-28 and last updated on 2026-06-17.
References
- http://www.securityfocus.com/bid/103567
- http://www.securitytracker.com/id/1040583
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-privesc1
Affected products (3)
- cpe:2.3:o:cisco:ios_xe:15.0\(5.59\)emd:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios_xe:16.1\(0\):*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios_xe:16.2\(0\):*:*:*:*:*:*:*
More vulnerabilities in Cisco Ios Xe
- CVE-2025-20188 — Critical (CVSS 10.0): A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client…
- CVE-2023-20198 — Critical (CVSS 10.0): Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco…
- CVE-2021-34770 — Critical (CVSS 10.0): A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE…
- CVE-2019-12643 — Critical (CVSS 10.0): A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allow an…
- CVE-2026-20272 — Critical (CVSS 9.8): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering…
- CVE-2021-1619 — Critical (CVSS 9.8): A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could…
All CVEs affecting Cisco Ios Xe →
Other CWE-78 (OS Command Injection) vulnerabilities
- CVE-2026-100382 — Critical (CVSS 10.0): Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia…
- CVE-2026-77521 — Critical (CVSS 10.0): MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool,…
- CVE-2026-82004 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS…
- CVE-2026-76197 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS…
- CVE-2026-76195 — Critical (CVSS 10.0): Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS…
- CVE-2026-19188 — Critical (CVSS 10.0): A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The…