{"schema_version":"public-product-v1.1","generated_at":"2026-07-21T11:04:27Z","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","advisory":{"id":"cisco-sa-20180620-fx-os-fabric-execution","slug":"cisco-sa-20180620-fx-os-fabric-execution","vendor":"Cisco","title":"Cisco FXOS and NX-OS Software Cisco Fabric Services Arbitrary Code Execution Vulnerability","summary":"A vulnerability in the Cisco&nbsp;Fabric Services&nbsp;(CFS) component of Cisco&nbsp;FXOS Software and Cisco&nbsp;NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability exists because the affected software insufficiently validates Cisco Fabric Services packet headers when the software processes packet data. An attacker could exploit this vulnerability by sending a maliciously crafted Cisco Fabric Services packet to an affected device. A successful exploit could allow the attacker to cause a buffer overflow condition on the device, which could allow the attacker to execute arbitrary code on the device. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fx-os-fabric-execution This advisory is part of the June 2018 Cisco FXOS and NX-OS Software Security Advisory Collection, which includes 24 Cisco Security Advisories that describe 24 vulnerabilities. For a complete list of the advisories and links to them, see Cisco Event Response: June 2018 Cisco FXOS and NX-OS Software Security Advisory Collection.","severity":"Critical","published_at":"2018-06-20T16:00:00Z","updated_at":"2018-07-05T21:11:00Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fx-os-fabric-execution","csaf_url":"https://sec.cloudapps.cisco.com/security/center/contentjson/CiscoSecurityAdvisory/cisco-sa-20180620-fx-os-fabric-execution/csaf/cisco-sa-20180620-fx-os-fabric-execution.json","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure."},"freshness":{"last_source_refreshed_at":"2026-07-21T05:16:34Z","latest_source_refresh_at":"2026-07-21T05:16:34Z","oldest_source_refresh_at":"2026-07-21T03:00:03Z","all_sources_fresh":true,"sources":[{"source":"cisco_advisories","label":"Cisco advisories","last_success_at":"2026-07-21T03:00:03Z","stale":false},{"source":"cisco_csaf","label":"Cisco CSAF","last_success_at":"2026-07-21T05:14:24Z","stale":false},{"source":"nvd_cves","label":"NVD CVEs","last_success_at":"2026-07-21T05:16:30Z","stale":false},{"source":"cisa_kev","label":"CISA KEV","last_success_at":"2026-07-21T05:16:31Z","stale":false},{"source":"first_epss","label":"EPSS","last_success_at":"2026-07-21T05:16:34Z","stale":false}]},"summary":{"cve_count":1,"visible_product_count":4,"public_evidence_count":4,"kev_count":0,"highest_epss":0.05958},"cves":[{"id":"CVE-2018-0314","kev":false,"epss":{"score":0.05958,"percentile":0.9248,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:33Z"}}],"public_evidence":[{"product":{"name":"Cisco Firepower Extensible Operating System (FXOS)","slug":"cisco-firepower-extensible-operating-system-fxos","vendor":"Cisco"},"cve":{"id":"CVE-2018-0314"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-20T05:11:16Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"Cisco Firepower Extensible Operating System (FXOS)","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"epss":{"score":0.05958,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:33Z"},"published_at":"2018-06-20T16:00:00Z","updated_at":"2018-07-05T21:11:00Z","advisory_updated_at":"2018-07-05T21:11:00Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fx-os-fabric-execution","remediation":{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fx-os-fabric-execution"},"row_display_order":1},{"product":{"name":"Cisco Unified Computing System (Managed)","slug":"cisco-unified-computing-system-managed","vendor":"Cisco"},"cve":{"id":"CVE-2018-0314"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-20T05:11:16Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"Cisco Unified Computing System (Managed)","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"epss":{"score":0.05958,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:33Z"},"published_at":"2018-06-20T16:00:00Z","updated_at":"2018-07-05T21:11:00Z","advisory_updated_at":"2018-07-05T21:11:00Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fx-os-fabric-execution","remediation":{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fx-os-fabric-execution"},"row_display_order":2},{"product":{"name":"Cisco NX-OS Software","slug":"cisco-nx-os-software","vendor":"Cisco"},"cve":{"id":"CVE-2018-0314"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-20T05:11:16Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"5.0(3)U1(1); 5.0(3)U1(1a); 5.0(3)U1(1b); 5.0(3)U1(1c); 5.0(3)U1(1d); 5.0(3)U1(2); 5.0(3)U1(2a); 5.0(3)U2(1); 5.0(3)U2(2); 5.0(3)U2(2a); 5.0(3)U2(2b); 5.0(3)U2(2c); 5.0(3)U2(2d); 5.0(3)U3(1); 5.0(3)U3(2); 5.0(3)U3(2a); 5.0(3)U3(2b); 5.0(3)U4(1); 5.0(3)U5(1); 5.0(3)U5(1a); 5.0(3)U5(1b); 5.0(3)U5(1c); 5.0(3)U5(1d); 5.0(3)U5(1e); 5.0(3)U5(1f); 5.0(3)U5(1g); 5.0(3)U5(1h); 5.0(3)U5(1i); 5.0(3)U5(1j); 6.0(2)A1(1); 6.0(2)A1(1a); 6.0(2)A1(1b); 6.0(2)A1(1c); 6.0(2)A1(1d); 6.0(2)A1(1e); 6.0(2)A1(1f); 6.0(2)A1(2d); 6.0(2)A3(1); 6.0(2)A3(2); 6.0(2)A3(4); 6.0(2)A4(1); 6.0(2)A4(2); 6.0(2)A4(3); 6.0(2)A4(4); 6.0(2)A4(5); 6.0(2)A4(6); 6.0(2)A6(1); 6.0(2)A6(1a); 6.0(2)A6(2); 6.0(2)A6(2a); 6.0(2)A6(3); 6.0(2)A6(3a); 6.0(2)A6(4); 6.0(2)A6(4a); 6.0(2)A6(5); 6.0(2)A6(5a); 6.0(2)A6(5b); 6.0(2)A6(6); 6.0(2)A6(7); 6.0(2)A6(8); 6.0(2)A7(1); 6.0(2)A7(1a); 6.0(2)A7(2); 6.0(2)A7(2a); 6.0(2)A8(1); 6.0(2)A8(2); 6.0(2)A8(3); 6.0(2)A8(4); 6.0(2)A8(4a); 6.0(2)A8(5); 6.0(2)A8(6); 6.0(2)A8(7); 6.0(2)A8(7a); 6.0(2)A8(7b); 6.0(2)A8(8); 6.0(2)A8(9); 6.0(2)N1(1); 6.0(2)N1(2); 6.0(2)N1(2a); 6.0(2)N2(1); 6.0(2)N2(1b); 6.0(2)N2(2); 6.0(2)N2(3); 6.0(2)N2(4); 6.0(2)N2(5); 6.0(2)N2(5a); 6.0(2)N2(6); 6.0(2)N2(7); 6.0(2)U1(1); 6.0(2)U1(1a); 6.0(2)U1(2); 6.0(2)U1(3); 6.0(2)U1(4); 6.0(2)U2(1); 6.0(2)U2(2); 6.0(2)U2(3); 6.0(2)U2(4); 6.0(2)U2(5); 6.0(2)U2(6); 6.0(2)U3(1); 6.0(2)U3(2); 6.0(2)U3(3); 6.0(2)U3(4); 6.0(2)U3(5); 6.0(2)U3(6); 6.0(2)U3(7); 6.0(2)U3(8); 6.0(2)U3(9); 6.0(2)U4(1); 6.0(2)U4(2); 6.0(2)U4(3); 6.0(2)U4(4); 6.0(2)U5(1); 6.0(2)U5(2); 6.0(2)U5(3); 6.0(2)U5(4); 6.0(2)U6(1); 6.0(2)U6(10); 6.0(2)U6(1a); 6.0(2)U6(2); 6.0(2)U6(2a); 6.0(2)U6(3); 6.0(2)U6(3a); 6.0(2)U6(4); 6.0(2)U6(4a); 6.0(2)U6(5); 6.0(2)U6(5a); 6.0(2)U6(5b); 6.0(2)U6(5c); 6.0(2)U6(6); 6.0(2)U6(7); 6.0(2)U6(8); 6.0(2)U6(9); 6.1(2)I1(1); 6.1(2)I1(2); 6.1(2)I1(3); 6.1(2)I2(1); 6.1(2)I2(2); 6.1(2)I2(2a); 6.1(2)I2(2b); 6.1(2)I2(3); 6.1(2)I3(1); 6.1(2)I3(2); 6.1(2)I3(3); 6.1(2)I3(3.78); 6.1(2)I3(3a); 6.1(2)I3(3b); 6.1(2)I3(4); 6.1(2)I3(4a); 6.1(2)I3(4b); 6.1(2)I3(4c); 6.1(2)I3(4d); 6.1(2)I3(4e); 6.1(2)I3(5); 6.1(2)I3(5a); 6.1(2)I3(5b); 6.2(10); 6.2(11b); 6.2(11c); 6.2(11d); 6.2(11e); 6.2(12); 6.2(13a); 6.2(13b); 6.2(14); 6.2(14a); 6.2(14b); 6.2(15); 6.2(16); 6.2(17); 6.2(18); 6.2(19); 6.2(2a); 6.2(5); 6.2(5a); 6.2(5b); 6.2(6); 6.2(6a); 6.2(6b); 6.2(8a); 6.2(8b); 6.2(9a); 6.2(9b); 6.2(9c); 7.0(0)N1(1); 7.0(1)N1(1); 7.0(2)I2(2c); 7.0(2)N1(1); 7.0(2)N1(1a); 7.0(3)F1(1); 7.0(3)F2(1); 7.0(3)F2(2); 7.0(3)I1(1); 7.0(3)I1(1a); 7.0(3)I1(1b); 7.0(3)I1(2); 7.0(3)I1(3); 7.0(3)I1(3a); 7.0(3)I1(3b); 7.0(3)I2(1); 7.0(3)I2(1a); 7.0(3)I2(2); 7.0(3)I2(2a); 7.0(3)I2(2b); 7.0(3)I2(2c); 7.0(3)I2(2d); 7.0(3)I2(2e); 7.0(3)I2(3); 7.0(3)I2(4); 7.0(3)I2(5); 7.0(3)I3(1); 7.0(3)I4(1); 7.0(3)I4(2); 7.0(3)I4(3); 7.0(3)I4(4); 7.0(3)I4(5); 7.0(3)I4(6); 7.0(3)I5(1); 7.0(3)I5(2); 7.0(3)I6(1); 7.0(3)N1(1); 7.0(4)N1(1); 7.0(4)N1(1a); 7.0(5)N1(1); 7.0(5)N1(1a); 7.0(6)N1(1); 7.0(6)N1(1c); 7.0(6)N1(2s); 7.0(6)N1(3s); 7.0(6)N1(4s); 7.0(7)N1(1); 7.0(7)N1(1a); 7.0(7)N1(1b); 7.0(8)N1(1); 7.0(8)N1(1a); 7.1(0)N1(1); 7.1(0)N1(1a); 7.1(0)N1(1b); 7.1(0)N1(2); 7.1(1)N1(1); 7.1(1)N1(1a); 7.1(2)N1(1); 7.1(2)N1(1a); 7.1(3)N1(1); 7.1(3)N1(1b); 7.1(3)N1(2); 7.1(3)N1(2a); 7.1(3)N1(3); 7.1(3)N1(4); 7.1(3)N1(5); 7.1(4)N1(1); 7.1(4)N1(1a); 7.1(4)N1(1c); 7.1(4)N1(1d); 7.2(0)D1(1); 7.2(0)N1(1); 7.2(1)D1(1); 7.2(1)N1(1); 7.2(2)D1(1); 7.2(2)D1(2); 7.3(0)D1(1); 7.3(0)DX(1); 7.3(0)N1(1); 7.3(0)N1(1a); 7.3(0)N1(1b); 7.3(1)D1(1); 7.3(1)D1(1B); 7.3(1)N1(0.1); 7.3(1)N1(1); 7.3(2)N1(1)","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"epss":{"score":0.05958,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:33Z"},"published_at":"2018-06-20T16:00:00Z","updated_at":"2018-07-05T21:11:00Z","advisory_updated_at":"2018-07-05T21:11:00Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fx-os-fabric-execution","remediation":{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fx-os-fabric-execution"},"row_display_order":3},{"product":{"name":"Cisco Adaptive Security Appliance (ASA) Software","slug":"cisco-adaptive-security-appliance-asa-software","vendor":"Cisco"},"cve":{"id":"CVE-2018-0314"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-20T05:11:16Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"6.2(1); 6.2(11); 6.2(13); 6.2(2); 6.2(3); 6.2(7); 6.2(8); 6.2(9); 7.0(3); 8.0(1); 8.1(1)","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"epss":{"score":0.05958,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:33Z"},"published_at":"2018-06-20T16:00:00Z","updated_at":"2018-07-05T21:11:00Z","advisory_updated_at":"2018-07-05T21:11:00Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fx-os-fabric-execution","remediation":{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180620-fx-os-fabric-execution"},"row_display_order":4}]}