cbcvebase.
CVE-2017-12233
published 2017-09-29

CVE-2017-12233: Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated…

PriorityP277high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
7.13%
93.6th percentile
Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of crafted CIP packets destined to an affected device. An attacker could exploit these vulnerabilities by sending crafted CIP packets to be processed by an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCuz95334.

Affected

2 ranges
VendorProductVersion rangeFixed in
ciscoios
ciscoios12.4 – 15.6

Detection & IOCsextracted from sources · hover to see the quote

  • Detect crafted CIP (Common Industrial Protocol) packets destined to Cisco IOS devices, which may trigger improper parsing and cause a device reload (DoS).
  • Monitor Cisco IOS devices (versions 12.4 through 15.6) for unexpected reloads, which may indicate exploitation of the CIP parsing vulnerability.
  • Track Cisco Bug IDs CSCuz95334 and CSCvc43709 when correlating vendor patch status against potentially vulnerable devices.
  • ·No workarounds are available for these vulnerabilities; only vendor software updates address them.
  • ·The vulnerability affects Cisco IOS Software with the CIP feature enabled across a wide version range (12.4 through 15.6); scope of exposure depends on whether CIP is active on the device.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vulncheck7.5HIGH
cisa7.5HIGH
vendor_cisco8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.