CVE-2017-12231
published 2017-09-29CVE-2017-12231: A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote…
PriorityP276high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
7.13%
93.6th percentile
A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to the improper translation of H.323 messages that use the Registration, Admission, and Status (RAS) protocol and are sent to an affected device via IPv4 packets. An attacker could exploit this vulnerability by sending a crafted H.323 RAS packet through an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition. This vulnerability affects Cisco devices that are configured to use an application layer gateway with NAT (NAT ALG) for H.323 RAS messages. By default, a NAT ALG is enabled for H.323 RAS messages. Cisco Bug IDs: CSCvc57217.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | 12.4 – 15.6 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger condition: crafted H.323 RAS (Registration, Admission, and Status) packet sent through a NAT-enabled Cisco IOS device via IPv4 — monitor for malformed H.323 RAS traffic traversing NAT boundaries ↗
- →Affected feature: NAT ALG for H.323 RAS is enabled by default — audit devices for 'ip nat service h323' or equivalent ALG configuration; devices without explicit disable are exposed ↗
- →Scope: only Cisco IOS versions 12.4 through 15.6 are affected — correlate device version strings in asset inventory to prioritise detection/patching ↗
- →Observable impact: successful exploitation causes device crash and reload — unexpected Cisco IOS reload events on NAT-enabled devices should be investigated as potential exploitation attempts ↗
- →Cisco Bug ID CSCvc57217 can be used to cross-reference vendor advisories, PSIRT feeds, and patch metadata for this specific vulnerability ↗
- ·Only devices configured to use NAT ALG for H.323 RAS messages are vulnerable — devices not performing NAT or with H.323 ALG explicitly disabled are not affected ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vulncheck7.5HIGH
cisa7.5HIGH
vendor_cisco8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability
cisa·2022-03-03·CVSS 7.5
CVE-2017-12231 [HIGH] CWE-399 Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability
Vulnerability: Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability
Affected: Cisco IOS software
A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS could allow an unauthenticated, remote attacker to cause a denial of service.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-12231
Remediation Due Date: 2022-03-24
Cisco
Cisco IOS Software Network Address Translation Denial of Service Vulnerability
vendor_cisco·2017-09-27·CVSS 8.6
CVE-2017-12231 [HIGH] CWE-399 Cisco IOS Software Network Address Translation Denial of Service Vulnerability
Cisco IOS Software Network Address Translation Denial of Service Vulnerability
A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
The vulnerability is due to the improper translation of H.323 messages that use the Registration, Admission, and Status (RAS) protocol and are sent to an affected device via IPv4 packets. An attacker could exploit this vulnerability by sending a crafted H.323 RAS packet through an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition.
Cisco has released software updates that address this vulnerabilit
Cisco
Cisco IOS Software Network Address Translation Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-12231 Cisco IOS Software Network Address Translation Denial of Service Vulnerability
CVE-2017-12231: Cisco IOS Software Network Address Translation Denial of Service Vulnerability
A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to the improper translation of H.323 messages that use the Registration, Admission, and Status (RAS) protocol and are sent to an affected device via IPv4 packets. An attacker could exploit this vulnerability by sending a crafted H.323 RAS packet through an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition. Cisco has released software updates that address this
GHSA
GHSA-83rp-43rf-7hmv: A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12
ghsa_unreviewed·2022-05-13
CVE-2017-12231 [HIGH] GHSA-83rp-43rf-7hmv: A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12
A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to the improper translation of H.323 messages that use the Registration, Admission, and Status (RAS) protocol and are sent to an affected device via IPv4 packets. An attacker could exploit this vulnerability by sending a crafted H.323 RAS packet through an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition. This vulnerability affects Cisco devices that are configured to use an application layer gateway with NAT (NAT ALG) for H.323 RAS messages.
VulnCheck
Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability
vulncheck·2017·CVSS 7.5
CVE-2017-12231 [HIGH] CWE-399 Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability
Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability
A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS could allow an unauthenticated, remote attacker to cause a denial of service.
Affected: Cisco IOS Software
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-20170927-nat.html
Remediation Due: 2022-03-24
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/101039http://www.securitytracker.com/id/1039449https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-nathttp://www.securityfocus.com/bid/101039http://www.securitytracker.com/id/1039449https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-nathttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-12231
2017-09-29
Published
2022-03-03
Added to CISA KEV
Exploited in the wild