CVE-2017-12232
published 2017-09-29CVE-2017-12232: A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through 15.6…
PriorityP277medium6.5CVSS 3.1
AVAACLPRNUINSUCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
2.17%
80.4th percentile
A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through 15.6 could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to a misclassification of Ethernet frames. An attacker could exploit this vulnerability by sending a crafted Ethernet frame to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvc03809.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | 15.0 – 15.6 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger condition is a crafted Ethernet frame sent to an affected Cisco ISR G2 device; monitor for unexpected device reloads on ISR G2 routers from adjacent network segments ↗
- →Root cause is misclassification of Ethernet frames in the protocol implementation; anomalous or malformed Ethernet frame types targeting ISR G2 interfaces should be flagged ↗
- →Attack vector is adjacent network (Layer 2); exploitation requires attacker to be on the same network segment — scope detection to L2-adjacent interfaces on ISR G2 devices ↗
- →Cisco internal bug tracker reference CSCvc03809 can be used to cross-reference vendor advisories and patch applicability checks ↗
- ·Vulnerability affects Cisco ISR G2 routers running Cisco IOS versions 15.0 through 15.6 only; scope detection and patching efforts to this platform and version range ↗
- ·No workarounds exist for this vulnerability; the only mitigation is applying Cisco's software updates ↗
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.06.1MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
vulncheck6.5MEDIUM
cisa6.5MEDIUM
vendor_cisco7.4HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j4ww-r9hh-57hx: A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15
ghsa_unreviewed·2022-05-13
CVE-2017-12232 [MEDIUM] GHSA-j4ww-r9hh-57hx: A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15
A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through 15.6 could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to a misclassification of Ethernet frames. An attacker could exploit this vulnerability by sending a crafted Ethernet frame to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvc03809.
VulnCheck
Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability
vulncheck·2017·CVSS 6.5
CVE-2017-12232 [MEDIUM] CWE-399 Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability
Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability
A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service.
Affected: Cisco IOS Software
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-20170927-rbip-dos.html
Remediation Due: 2022-03-24
CISA
Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability
cisa·2022-03-03·CVSS 6.5
CVE-2017-12232 [MEDIUM] CWE-399 Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability
Vulnerability: Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability
Affected: Cisco IOS software
A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-12232
Remediation Due Date: 2022-03-24
Cisco
Cisco IOS Software for Cisco Integrated Services Routers Generation 2 Denial of Service Vulnerability
vendor_cisco·2017-09-27·CVSS 7.4
CVE-2017-12232 [HIGH] CWE-399 Cisco IOS Software for Cisco Integrated Services Routers Generation 2 Denial of Service Vulnerability
Cisco IOS Software for Cisco Integrated Services Routers Generation 2 Denial of Service Vulnerability
A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.
The vulnerability is due to a misclassification of Ethernet frames. An attacker could exploit this vulnerability by sending a crafted Ethernet frame to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerabil
Cisco
Cisco IOS Software for Cisco Integrated Services Routers Generation 2 Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-12232 Cisco IOS Software for Cisco Integrated Services Routers Generation 2 Denial of Service Vulnerability
CVE-2017-12232: Cisco IOS Software for Cisco Integrated Services Routers Generation 2 Denial of Service Vulnerability
A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to a misclassification of Ethernet frames. An attacker could exploit this vulnerability by sending a crafted Ethernet frame to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-399, CWE
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/101044http://www.securitytracker.com/id/1039452https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-rbip-doshttp://www.securityfocus.com/bid/101044http://www.securitytracker.com/id/1039452https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-rbip-doshttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-12232
2017-09-29
Published
2022-03-03
Added to CISA KEV
Exploited in the wild