CVE-2018-0150

CRITICAL EXPLOITED

Cisco IOS XE 16.x - Unauthenticated Use of Hard-coded Credentials

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2018-0150 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

A vulnerability in Cisco IOS XE Software could allow an unauthenticated, remote attacker to log in to a device running an affected release of Cisco IOS XE Software with the default username and password that are used at initial boot, aka a Static Credential Vulnerability. The vulnerability is due to an undocumented user account with privilege level 15 that has a default username and password. An attacker could exploit this vulnerability by using this account to remotely connect to an affected device. A successful exploit could allow the attacker to log in to the device with privilege level 15 access. This vulnerability affects Cisco devices that are running a vulnerable release of Cisco IOS XE Software Release 16.x. This vulnerability does not affect Cisco IOS XE Software releases prior to Release 16.x. Cisco Bug IDs: CSCve89880.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/103539
Mitigation, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1040579

Scores

CVSS v3 9.8
EPSS 0.0434
EPSS Percentile 89.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2025-05-16
CWE
CWE-798
Status published
Products (1)
cisco/ios_xe 16.5.1
Published Mar 28, 2018
Tracked Since Feb 18, 2026