cbcvebase.
CVE-2017-12231
published 2017-09-29

CVE-2017-12231: A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote…

PriorityP276high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
7.13%
93.6th percentile
A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to the improper translation of H.323 messages that use the Registration, Admission, and Status (RAS) protocol and are sent to an affected device via IPv4 packets. An attacker could exploit this vulnerability by sending a crafted H.323 RAS packet through an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition. This vulnerability affects Cisco devices that are configured to use an application layer gateway with NAT (NAT ALG) for H.323 RAS messages. By default, a NAT ALG is enabled for H.323 RAS messages. Cisco Bug IDs: CSCvc57217.

Affected

2 ranges
VendorProductVersion rangeFixed in
ciscoios
ciscoios12.4 – 15.6

Detection & IOCsextracted from sources · hover to see the quote

  • Trigger condition: crafted H.323 RAS (Registration, Admission, and Status) packet sent through a NAT-enabled Cisco IOS device via IPv4 — monitor for malformed H.323 RAS traffic traversing NAT boundaries
  • Affected feature: NAT ALG for H.323 RAS is enabled by default — audit devices for 'ip nat service h323' or equivalent ALG configuration; devices without explicit disable are exposed
  • Scope: only Cisco IOS versions 12.4 through 15.6 are affected — correlate device version strings in asset inventory to prioritise detection/patching
  • Observable impact: successful exploitation causes device crash and reload — unexpected Cisco IOS reload events on NAT-enabled devices should be investigated as potential exploitation attempts
  • Cisco Bug ID CSCvc57217 can be used to cross-reference vendor advisories, PSIRT feeds, and patch metadata for this specific vulnerability
  • ·Only devices configured to use NAT ALG for H.323 RAS messages are vulnerable — devices not performing NAT or with H.323 ALG explicitly disabled are not affected

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vulncheck7.5HIGH
cisa7.5HIGH
vendor_cisco8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.