Evidence dossier

CVE-2018-0158

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a…

Exploited in the wild (CISA KEV since Mar 3, 2022). NVD reports CVSS 3.1 8.6. EPSS estimates 7.2% exploit likelihood as of Aug 27, 2026.

70.471.7Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain IKEv2 packets. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device to be processed. A successful exploit could cause an affected device to continuously consume memory and eventually reload, resulting in a DoS condition. Cisco Bug IDs: CSCvf22394.

State
PUBLISHED
Published
Mar 28, 2018
Updated
Jan 12, 2026
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    cisco

    Record text: A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain IKEv2 packets. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device to be processed. A successful exploit could cause an affected device to continuously consume memory and eventually reload, resulting in a DoS condition. Cisco Bug IDs: CSCvf22394.

    Inspect raw assertion
    Field
    container
    Value
    A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain IKEv2 packets. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device to be processed. A successful exploit could cause an affected device to continuously consume memory and eventually reload, resulting in a DoS condition. Cisco Bug IDs: CSCvf22394.
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 7.24% probability · 93.86th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.072370000000; percentile 0.938620000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Mar 3, 2022 · first observed Jul 19, 2026

Exploit likelihood7.24%

FIRST EPSS · score date Aug 27, 2026 · 93.9th percentile · first observed Aug 27, 2026

SeverityCVSS 8.6

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
ciscoOriginal assertion
Record text

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain IKEv2 packets. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device to be processed. A successful exploit could cause an affected device to continuously consume memory and eventually reload, resulting in a DoS condition. Cisco Bug IDs: CSCvf22394.

Inspect raw assertion
Field
container
Value
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain IKEv2 packets. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device to be processed. A successful exploit could cause an affected device to continuously consume memory and eventually reload, resulting in a DoS condition. Cisco Bug IDs: CSCvf22394.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

7.24% probability · 93.86th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.072370000000; percentile 0.938620000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
59Underlying assertions
12Canonical products
40Target assertions
19Constraint assertions

Grouped from 6 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

13 scope groups

cisco · source assertedn/aCisco IOS and IOS XEDirect source scope
Affected: Cisco IOS and IOS XE
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "Cisco IOS and IOS XE"}]
NVD CPE · HARDWAREciscoasr_1001-hxEnvironmental constraint · 2 assertions
Version not applicableCanonical identity product-6ffe3f078b1fbff1bfaf1195da5632a15ea59dc998a11bf56f0b0bc98dea5ac5Linked exact
Scope constrained
Inspect raw assertions
  1. cpe:2.3:h:cisco:asr_1001-hx:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7594e307-ac80-41ec-ae94-07e664a7d701
  2. cpe:2.3:h:cisco:asr_1001-hx:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7594e307-ac80-41ec-ae94-07e664a7d701
NVD CPE · HARDWAREciscoasr_1001-xEnvironmental constraint · 2 assertions
Version not applicableCanonical identity product-7d1996aa2655aeb23e3a03b6489799ad416e8aedbd6d10e55e901d21c5bdaad1Linked exact
Scope constrained
Inspect raw assertions
  1. cpe:2.3:h:cisco:asr_1001-x:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    09c913ff-63d5-43fb-8b39-598ef436ba5a
  2. cpe:2.3:h:cisco:asr_1001-x:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    09c913ff-63d5-43fb-8b39-598ef436ba5a
NVD CPE · HARDWAREciscoasr_1002-hxEnvironmental constraint · 2 assertions
Version not applicableCanonical identity product-c0422ee07daa7be79700aded194408e1fc7fb1a9661a2d1d08c4d893f9c57ceaLinked exact
Scope constrained
Inspect raw assertions
  1. cpe:2.3:h:cisco:asr_1002-hx:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cd2794bd-c8ce-46ef-9857-1723fcf04e46
  2. cpe:2.3:h:cisco:asr_1002-hx:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cd2794bd-c8ce-46ef-9857-1723fcf04e46
NVD CPE · HARDWAREciscoasr_1002-xEnvironmental constraint · 2 assertions
Version not applicableCanonical identity product-7230cfe2ce5feb0072a6db1bfe3a1c9341bb2640d5c4a2f0f4778020fecd8ee3Linked exact
Scope constrained
Inspect raw assertions
  1. cpe:2.3:h:cisco:asr_1002-x:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    444f688f-79d0-4f22-b530-7bd520080b8f
  2. cpe:2.3:h:cisco:asr_1002-x:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    444f688f-79d0-4f22-b530-7bd520080b8f
NVD CPE · HARDWAREciscoasr_1004Environmental constraint · 2 assertions
Version not applicableCanonical identity product-77ddba0a393d5ce6b5584f307d92799d7a361f231701ddccebbcc6a08b462114Linked exact
Scope constrained
Inspect raw assertions
  1. cpe:2.3:h:cisco:asr_1004:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    55dd2272-10c2-43b9-9f13-6dc41dbe179b
  2. cpe:2.3:h:cisco:asr_1004:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    55dd2272-10c2-43b9-9f13-6dc41dbe179b
NVD CPE · HARDWAREciscoasr_1006Environmental constraint · 2 assertions
Version not applicableCanonical identity product-f6aea74e14dd2b9ce3abd157139dbdbee216238ef6dcd6bc5da45e9564fafabeLinked exact
Scope constrained
Inspect raw assertions
  1. cpe:2.3:h:cisco:asr_1006:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7428e0a8-1641-47fb-9ca9-34311def660d
  2. cpe:2.3:h:cisco:asr_1006:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7428e0a8-1641-47fb-9ca9-34311def660d
NVD CPE · HARDWAREciscoasr_1006-xEnvironmental constraint · 2 assertions
Version not applicableCanonical identity product-2eae567f62fce4b7f35fd0ea5db212df8dc2dab49bd477016c28aad21722649eLinked exact
Scope constrained
Inspect raw assertions
  1. cpe:2.3:h:cisco:asr_1006-x:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    de7401b7-094c-46eb-9869-2f0372e8b26b
  2. cpe:2.3:h:cisco:asr_1006-x:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    de7401b7-094c-46eb-9869-2f0372e8b26b
NVD CPE · HARDWAREciscoasr_1009-xEnvironmental constraint · 2 assertions
Version not applicableCanonical identity product-eaf6ddc48fb7d971f8a6c09625f0c925d4b1a39fddbf83089a32ca42c92d8238Linked exact
Scope constrained
Inspect raw assertions
  1. cpe:2.3:h:cisco:asr_1009-x:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8d8a72fd-d8b0-45b5-8fad-6d8395bb218a
  2. cpe:2.3:h:cisco:asr_1009-x:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8d8a72fd-d8b0-45b5-8fad-6d8395bb218a
NVD CPE · HARDWAREciscoasr_1013Environmental constraint · 2 assertions
Version not applicableCanonical identity product-5a8e3a6e907c7e4515995f47e4033280ea911ac46ebe92d5c5040b61790a8383Linked exact
Scope constrained
Inspect raw assertions
  1. cpe:2.3:h:cisco:asr_1013:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    854d9594-fe84-4e7b-ba21-a3287f2dc302
  2. cpe:2.3:h:cisco:asr_1013:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    854d9594-fe84-4e7b-ba21-a3287f2dc302
NVD CPE · OPERATING SYSTEMciscoiosVulnerable target · 20 assertions
Version 15.5(3)s1.1; Version 15.5(3)s1.10; Version 15.5(3)s1.11; Version 15.5(3)s1.12; Version 15.5(3)s1.2; Version 15.5(3)s1.4; Version 15.5(3)s1.5; Version 15.5(3)s1.7; Version 15.5(3)s1.8; Version 15.5(3)s1.9Canonical identity product-5972f4392170d0d1b4e75a10eb3b383835ead601c8d9b09329525407a4e1471aLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:cisco:ios:15.5\(3\)s1.8:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e878525d-7ff5-42c7-899b-8c56360246c9
  2. cpe:2.3:o:cisco:ios:15.5\(3\)s1.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3126916b-968a-4c85-a963-1aaa418db52e
  3. cpe:2.3:o:cisco:ios:15.5\(3\)s1.11:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    75421c15-4e2a-4f56-abd8-4592e686b60e
  4. cpe:2.3:o:cisco:ios:15.5\(3\)s1.2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1cfec4b0-3ea4-40d3-a197-7942f4a9807c
  5. cpe:2.3:o:cisco:ios:15.5\(3\)s1.11:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    75421c15-4e2a-4f56-abd8-4592e686b60e
  6. cpe:2.3:o:cisco:ios:15.5\(3\)s1.4:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1bb36c60-f393-4fc1-ade8-b83faabbb17b
  7. cpe:2.3:o:cisco:ios:15.5\(3\)s1.8:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e878525d-7ff5-42c7-899b-8c56360246c9
  8. cpe:2.3:o:cisco:ios:15.5\(3\)s1.9:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d2f0ad0e-313f-49ff-ad9a-0dfb643d38a0
  9. cpe:2.3:o:cisco:ios:15.5\(3\)s1.12:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    00b75eed-9a20-4c5f-907e-e1c73476b700
  10. cpe:2.3:o:cisco:ios:15.5\(3\)s1.5:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e807206f-26a1-40ff-a3ac-f819660d4ab1
  11. cpe:2.3:o:cisco:ios:15.5\(3\)s1.7:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e769d555-76b6-4ef0-8996-87b8775d40ec
  12. cpe:2.3:o:cisco:ios:15.5\(3\)s1.5:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e807206f-26a1-40ff-a3ac-f819660d4ab1
  13. cpe:2.3:o:cisco:ios:15.5\(3\)s1.9:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d2f0ad0e-313f-49ff-ad9a-0dfb643d38a0
  14. cpe:2.3:o:cisco:ios:15.5\(3\)s1.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3126916b-968a-4c85-a963-1aaa418db52e
  15. cpe:2.3:o:cisco:ios:15.5\(3\)s1.10:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b2c28ad2-24cd-49dd-8883-4c4351e8a3f8
  16. cpe:2.3:o:cisco:ios:15.5\(3\)s1.7:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e769d555-76b6-4ef0-8996-87b8775d40ec
  17. cpe:2.3:o:cisco:ios:15.5\(3\)s1.4:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1bb36c60-f393-4fc1-ade8-b83faabbb17b
  18. cpe:2.3:o:cisco:ios:15.5\(3\)s1.2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1cfec4b0-3ea4-40d3-a197-7942f4a9807c
  19. cpe:2.3:o:cisco:ios:15.5\(3\)s1.12:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    00b75eed-9a20-4c5f-907e-e1c73476b700
  20. cpe:2.3:o:cisco:ios:15.5\(3\)s1.10:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b2c28ad2-24cd-49dd-8883-4c4351e8a3f8
NVD CPE · OPERATING SYSTEMciscoios_xeVulnerable target · 20 assertions
Version 15.5(3)s1.1; Version 15.5(3)s1.10; Version 15.5(3)s1.11; Version 15.5(3)s1.12; Version 15.5(3)s1.2; Version 15.5(3)s1.4; Version 15.5(3)s1.5; Version 15.5(3)s1.7; Version 15.5(3)s1.8; Version 15.5(3)s1.9Canonical identity product-cc06181059d0f387414dd5737700c03a38fe93d65d4a541ac9744a37c25c9f59Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:cisco:ios_xe:15.5\(3\)s1.9:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    28258348-0537-41d9-801e-22f771bc9d87
  2. cpe:2.3:o:cisco:ios_xe:15.5\(3\)s1.11:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fb2edc53-4bed-40cc-bc76-d714fb637f47
  3. cpe:2.3:o:cisco:ios_xe:15.5\(3\)s1.5:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b951a529-f0eb-4042-a2b9-c7d37d4ccb94
  4. cpe:2.3:o:cisco:ios_xe:15.5\(3\)s1.2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ace49e6b-9de9-4aa3-8aa1-58958d98bd5a
  5. cpe:2.3:o:cisco:ios_xe:15.5\(3\)s1.9:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    28258348-0537-41d9-801e-22f771bc9d87
  6. cpe:2.3:o:cisco:ios_xe:15.5\(3\)s1.11:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fb2edc53-4bed-40cc-bc76-d714fb637f47
  7. cpe:2.3:o:cisco:ios_xe:15.5\(3\)s1.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c4ef130d-747b-4a10-84e9-94796c819755
  8. cpe:2.3:o:cisco:ios_xe:15.5\(3\)s1.5:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b951a529-f0eb-4042-a2b9-c7d37d4ccb94
  9. cpe:2.3:o:cisco:ios_xe:15.5\(3\)s1.4:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    97e48cd3-1c0b-4925-a852-3fff5afbf67c
  10. cpe:2.3:o:cisco:ios_xe:15.5\(3\)s1.8:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bb99039d-ba07-45fc-85e8-691af9d0b764
  11. cpe:2.3:o:cisco:ios_xe:15.5\(3\)s1.8:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bb99039d-ba07-45fc-85e8-691af9d0b764
  12. cpe:2.3:o:cisco:ios_xe:15.5\(3\)s1.10:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a533bcc3-5c12-41f3-b43e-11121d74f623
  13. cpe:2.3:o:cisco:ios_xe:15.5\(3\)s1.4:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    97e48cd3-1c0b-4925-a852-3fff5afbf67c
  14. cpe:2.3:o:cisco:ios_xe:15.5\(3\)s1.12:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    74a50d40-737e-4b9f-bde0-19f111b5a98b
  15. cpe:2.3:o:cisco:ios_xe:15.5\(3\)s1.2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ace49e6b-9de9-4aa3-8aa1-58958d98bd5a
  16. cpe:2.3:o:cisco:ios_xe:15.5\(3\)s1.7:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    dfbda3e6-17f0-45b9-8dc4-6a90b45272d7
  17. cpe:2.3:o:cisco:ios_xe:15.5\(3\)s1.12:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    74a50d40-737e-4b9f-bde0-19f111b5a98b
  18. cpe:2.3:o:cisco:ios_xe:15.5\(3\)s1.7:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    dfbda3e6-17f0-45b9-8dc4-6a90b45272d7
  19. cpe:2.3:o:cisco:ios_xe:15.5\(3\)s1.10:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a533bcc3-5c12-41f3-b43e-11121d74f623
  20. cpe:2.3:o:cisco:ios_xe:15.5\(3\)s1.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c4ef130d-747b-4a10-84e9-94796c819755
NVD CPE · HARDWARErockwellautomationallen-bradley_stratix_5900Environmental constraint · 1 assertions
Version not applicableCanonical identity product-4dc92f03840829c22a031bbd0fab20074744a1fea21ddca61313694e85121613Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:rockwellautomation:allen-bradley_stratix_5900:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1609d07f-ff2d-49d8-8672-9c512a69479d

Affected-product evidence

Accepted scope and product mapping

2 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-0774b265c0e837e737aaf99ed0f2450c048e61f34267ca59d8623878b839334e · product-5972f4392170d0d1b4e75a10eb3b383835ead601c8d9b09329525407a4e1471a

Source class
Nvd cpe vulnerable target
Assertions
20
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0572b964-5c21-4003-9f06-5842e62e57ce1ca4c17a-62f6-4cff-86ae-3afa0c072a4620d99684-ccd2-4dd1-8e3b-42759747d6e62451f75f-4f86-48de-a2d9-9941940c97dc2474e772-555c-450c-a03b-69c5a5ec6bed33b7a0f9-1963-4219-bd38-4090c3bba1d43c657f03-6fab-4ab2-8e0c-3f630a70f51542e56d28-cea2-495f-a7ea-1976a88decab472a7c2e-913f-4033-aec5-db2b064d57a354daa51a-b899-4084-b350-bfc13e9450bc7d6eeac8-7a7b-4e0e-8016-02a25919930383eb2cdb-8d8c-4bf3-b742-539f98ff27ca89a4d0d4-9d36-4dda-9b27-fb855d3419aa99eb91ce-f52f-4617-be6c-1e014ef261b09e8a574c-ca2a-42da-bfc0-b14c597f7c4cbd2839ad-b252-4c99-b4fa-0c56b17a292abd5aa463-9df9-4aac-8971-372154ea629ac9605482-30a9-40b7-9b91-137ea42c0b6fd0f40a96-4ff7-4d56-8e4b-6114f062ce10faec86b9-b9a4-4a92-84ef-ed2e6db4199b
Mapping establishedEvidence supported

vendor-0774b265c0e837e737aaf99ed0f2450c048e61f34267ca59d8623878b839334e · product-cc06181059d0f387414dd5737700c03a38fe93d65d4a541ac9744a37c25c9f59

Source class
Nvd cpe vulnerable target
Assertions
20
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
18e874bd-5315-4525-9e11-1cb4c23028af2603e925-eac9-4785-a4f4-8572c2d69d9a2d3b54c2-c5f8-4ea2-b4b1-4a08b1c7cd2a3451f5a1-caad-4710-b2c1-904cfcc7b1124346de0f-2767-49b3-af0e-53017fa35702502116d5-8ecf-4d63-89c3-d01ff78050d95fdac57a-6260-4d4a-9dfc-64db06dd427f6d20874b-f8ef-4f78-a303-49fdbaa1f06b76400f58-c226-43c7-96ba-9d2cf60b50e77bbdd1f4-0d25-4bb4-b625-2ee71803437d9476ffde-9a11-4645-b3c0-8e34d69d4dbe9e4ca0a2-4704-4a8c-87ec-996eb0c75754a2b17bba-544c-45ea-9c3a-a433fe91e125cfef9187-97a6-40ea-af3c-efd82a4db583d3627adf-7fca-40ad-84ab-f389afa058e0d906c612-60a3-47b7-85f9-ecf94d0398f9dfb91a13-b99e-4c36-89fe-fa1dacac1112e0710431-3c9f-4e63-9987-f7fd15a07206e7f155fe-5923-4242-a698-f768fa7be1a1ea467968-3332-4210-9795-aee02b2da24a
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
e78703e2-b454-440b-8093-35f4b5f68462

Assessments

CVSS by origin

8.6
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
7.8
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:L/Au:N/C:N/I:N/A:C
8.6
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
8.6
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Direct CVE/CNA normalized decisions

8.6Priority eligible

CISA-ADP

CVSS 3.1 · Secondary · Independent enrichment · rank 2

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Validation
Valid match
Recomputed
8.6
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.