CVE-2017-12234
published 2017-09-29CVE-2017-12234: Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated…
PriorityP277high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
7.13%
93.6th percentile
Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of crafted CIP packets destined to an affected device. An attacker could exploit these vulnerabilities by sending crafted CIP packets to be processed by an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvc43709.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | 12.4 – 15.6 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect crafted CIP (Common Industrial Protocol) packets destined to Cisco IOS devices; malformed/improper CIP parsing triggers a device reload (DoS) ↗
- →Monitor for unexpected Cisco IOS device reloads originating from CIP traffic; unauthenticated remote exploitation means no prior session establishment is required ↗
- →Reference Cisco Bug IDs CSCuz95334 and CSCvc43709 when correlating vendor logs or TAC cases for this vulnerability ↗
- ·Affected software versions span Cisco IOS 12.4 through 15.6; only devices with the CIP feature enabled are vulnerable ↗
- ·There are no workarounds available; the only mitigation is applying vendor-supplied software updates ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vulncheck7.5HIGH
cisa7.5HIGH
vendor_cisco8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability
cisa·2022-03-03·CVSS 7.5
CVE-2017-12234 [HIGH] CWE-20 Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability
Vulnerability: Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability
Affected: Cisco IOS software
There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-12234
Remediation Due Date: 2022-03-24
Cisco
Cisco IOS Software Common Industrial Protocol Request Denial of Service Vulnerabilities
vendor_cisco·2017-09-27·CVSS 8.6
CVE-2017-12233 [HIGH] CWE-20 Cisco IOS Software Common Industrial Protocol Request Denial of Service Vulnerabilities
Cisco IOS Software Common Industrial Protocol Request Denial of Service Vulnerabilities
Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.
The vulnerabilities are due to the improper parsing of crafted CIP packets destined to an affected device. An attacker could exploit these vulnerabilities by sending crafted CIP packets to be processed by an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address thes
Cisco
Cisco IOS Software Common Industrial Protocol Request Denial of Service Vulnerabilities
vendor_cisco·CVSS 3.0
CVE-2017-12234 Cisco IOS Software Common Industrial Protocol Request Denial of Service Vulnerabilities
CVE-2017-12234: Cisco IOS Software Common Industrial Protocol Request Denial of Service Vulnerabilities
Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of crafted CIP packets destined to an affected device. An attacker could exploit these vulnerabilities by sending crafted CIP packets to be processed by an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco has released software updates that address these vulnerabilities. There are no
CVSS: 3.0
CWE: C
GHSA
GHSA-89f3-gxqw-p6pq: Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12
ghsa_unreviewed·2022-05-13
CVE-2017-12234 [HIGH] CWE-20 GHSA-89f3-gxqw-p6pq: Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12
Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of crafted CIP packets destined to an affected device. An attacker could exploit these vulnerabilities by sending crafted CIP packets to be processed by an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvc43709.
VulnCheck
Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability
vulncheck·2017·CVSS 7.5
CVE-2017-12234 [HIGH] CWE-20 Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability
Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability
There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.
Affected: Cisco IOS Software
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-20170927-cip.html
Remediation Due: 2022-03-24
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/101038http://www.securitytracker.com/id/1039459https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-ciphttp://www.securityfocus.com/bid/101038http://www.securitytracker.com/id/1039459https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-ciphttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-12234
2017-09-29
Published
2022-03-03
Added to CISA KEV
Exploited in the wild