CVE-2017-12233
published 2017-09-29CVE-2017-12233: Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated…
PriorityP277high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
7.13%
93.6th percentile
Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of crafted CIP packets destined to an affected device. An attacker could exploit these vulnerabilities by sending crafted CIP packets to be processed by an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCuz95334.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | 12.4 – 15.6 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect crafted CIP (Common Industrial Protocol) packets destined to Cisco IOS devices, which may trigger improper parsing and cause a device reload (DoS). ↗
- →Monitor Cisco IOS devices (versions 12.4 through 15.6) for unexpected reloads, which may indicate exploitation of the CIP parsing vulnerability. ↗
- →Track Cisco Bug IDs CSCuz95334 and CSCvc43709 when correlating vendor patch status against potentially vulnerable devices. ↗
- ·No workarounds are available for these vulnerabilities; only vendor software updates address them. ↗
- ·The vulnerability affects Cisco IOS Software with the CIP feature enabled across a wide version range (12.4 through 15.6); scope of exposure depends on whether CIP is active on the device. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vulncheck7.5HIGH
cisa7.5HIGH
vendor_cisco8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability
cisa·2022-03-03·CVSS 7.5
CVE-2017-12233 [HIGH] CWE-20 Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability
Vulnerability: Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability
Affected: Cisco IOS software
There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-12233
Remediation Due Date: 2022-03-24
Cisco
Cisco IOS Software Common Industrial Protocol Request Denial of Service Vulnerabilities
vendor_cisco·2017-09-27·CVSS 8.6
CVE-2017-12233 [HIGH] CWE-20 Cisco IOS Software Common Industrial Protocol Request Denial of Service Vulnerabilities
Cisco IOS Software Common Industrial Protocol Request Denial of Service Vulnerabilities
Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.
The vulnerabilities are due to the improper parsing of crafted CIP packets destined to an affected device. An attacker could exploit these vulnerabilities by sending crafted CIP packets to be processed by an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address thes
Cisco
Cisco IOS Software Common Industrial Protocol Request Denial of Service Vulnerabilities
vendor_cisco·CVSS 3.0
CVE-2017-12233 Cisco IOS Software Common Industrial Protocol Request Denial of Service Vulnerabilities
CVE-2017-12233: Cisco IOS Software Common Industrial Protocol Request Denial of Service Vulnerabilities
Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of crafted CIP packets destined to an affected device. An attacker could exploit these vulnerabilities by sending crafted CIP packets to be processed by an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco has released software updates that address these vulnerabilities. There are no
CVSS: 3.0
CWE: C
GHSA
GHSA-h9rm-4rp6-464p: Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12
ghsa_unreviewed·2022-05-13
CVE-2017-12233 [HIGH] CWE-20 GHSA-h9rm-4rp6-464p: Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12
Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of crafted CIP packets destined to an affected device. An attacker could exploit these vulnerabilities by sending crafted CIP packets to be processed by an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCuz95334.
VulnCheck
Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability
vulncheck·2017·CVSS 7.5
CVE-2017-12233 [HIGH] CWE-20 Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability
Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability
There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.
Affected: Cisco IOS Software
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-20170927-cip.html
Remediation Due: 2022-03-24
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/101038http://www.securitytracker.com/id/1039459https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-ciphttp://www.securityfocus.com/bid/101038http://www.securitytracker.com/id/1039459https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-ciphttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-12233
2017-09-29
Published
2022-03-03
Added to CISA KEV
Exploited in the wild