This vulnerability affects Cisco devices that are running a vulnerable release of Cisco IOS or IOS XE Software and have the Smart Install client feature enabled. Only Smart install client switches affected by the vulnerability that is described in this advisory are affected by this vulnerability. Smart Install is enabled by default on Cisco Catalyst Switches that have not been updated to address Cisco bug ID CSCvd36820. Switches are not capable of running Smart Install, but they can be Smart Install clients if they support the archive download-switching privileged EXEC command.”]
Source: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2