CVE-2017-12211Cisco IOS vulnerability

CWE-3994 documents4 sources
Severity
5.3MEDIUMNVD
EPSS
1.1%
top 21.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 7
Latest updateMay 13

Description

A vulnerability in the IPv6 Simple Network Management Protocol (SNMP) code of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to cause high CPU usage or a reload of the device. The vulnerability is due to IPv6 sub block corruption. An attacker could exploit this vulnerability by polling the affected device IPv6 information. An exploit could allow the attacker to trigger high CPU usage or a reload of the device. Known Affected Releases: Denali-16.3.1. Cisco Bug I

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.6 | Impact: 3.6

Affected Packages2 packages

NVDcisco/ios3.16.1
NVDcisco/ios_xe3.16.1

🔴Vulnerability Details

2
GHSA
GHSA-7664-hhqm-4p3m: A vulnerability in the IPv6 Simple Network Management Protocol (SNMP) code of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote2022-05-13
CVEList
CVE-2017-12211: A vulnerability in the IPv6 Simple Network Management Protocol (SNMP) code of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote2017-09-07

📋Vendor Advisories

1
Cisco
Cisco IOS and Cisco IOS XE Software IPv6 SNMP Message Handling Denial of Service Vulnerability2017-09-06
CVE-2017-12211 — Cisco IOS vulnerability | cvebase