Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
- Severity
- Critical9.8CVSS 3.1, Critical
- EPSS
- 99%
- Published
- 28 Mar 2018
- Updated
- 17 Jun 2026
Description
Title, description and vendor guidance are quoted from the source records.
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute arbitrary code on an affected device. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted Smart Install message to an affected device on TCP port 4786. A successful exploit could allow the attacker to cause a buffer overflow on the affected device, which could have the following impacts: Triggering a reload of the device, Allowing the attacker to execute arbitrary code on the device, Causing an indefinite loop on the affected device that triggers a watchdog crash. Cisco Bug IDs: CSCvg76186.
Weakness: CWE-20, CWE-787
Known exploited
Added to CISA KEV on 3 Nov 2021
Federal remediation due date: 3 May 2022
Required action: Apply updates per vendor instructions.
Exploit prediction
99% probability of exploitation in the next 30 days (percentile 100%).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Patcharo shows this vulnerability for information but does not match versions for this product yet.
- n/a Cisco IOS and IOS XE · Cisco IOS and IOS XE
References
- https://ics-cert.us-cert.gov/advisories/ICSA-18-107-04(opens in a new tab)
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2(opens in a new tab)
- https://www.darkreading.com/perimeter/attackers-exploit-cisco-switch-issue-as-vendor-warns-of-yet-another-critical-flaw/d/d-id/1331490(opens in a new tab)
- https://ics-cert.us-cert.gov/advisories/ICSA-18-107-05(opens in a new tab)
Provenance
Every fact on this page comes from the sources below. Nothing is written by an AI.
- Cisco (CVE record)
- Cisco (CVE record) · 27 Sept 2026, 23:46 UTC · Parser patcharo-cve5/1.1.0
- CISA Known Exploited Vulnerabilities
- CISA Known Exploited Vulnerabilities · 27 Sept 2026, 23:42 UTC · Parser patcharo-kev/1.0.0
- NVD
- NVD · 27 Sept 2026, 23:44 UTC · Parser patcharo-nvd/1.0.0
- FIRST EPSS
- FIRST EPSS · 27 Sept 2026, 23:46 UTC · Parser patcharo-epss/1.0.0
Last verified: 28 Sept 2026, 02:31 UTC