cbcvebase.
CVE-2017-12234
published 2017-09-29

CVE-2017-12234: Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated…

PriorityP277high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
7.13%
93.6th percentile
Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of crafted CIP packets destined to an affected device. An attacker could exploit these vulnerabilities by sending crafted CIP packets to be processed by an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvc43709.

Affected

2 ranges
VendorProductVersion rangeFixed in
ciscoios
ciscoios12.4 – 15.6

Detection & IOCsextracted from sources · hover to see the quote

  • Detect crafted CIP (Common Industrial Protocol) packets destined to Cisco IOS devices; malformed/improper CIP parsing triggers a device reload (DoS)
  • Monitor for unexpected Cisco IOS device reloads originating from CIP traffic; unauthenticated remote exploitation means no prior session establishment is required
  • Reference Cisco Bug IDs CSCuz95334 and CSCvc43709 when correlating vendor logs or TAC cases for this vulnerability
  • ·Affected software versions span Cisco IOS 12.4 through 15.6; only devices with the CIP feature enabled are vulnerable
  • ·There are no workarounds available; the only mitigation is applying vendor-supplied software updates

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vulncheck7.5HIGH
cisa7.5HIGH
vendor_cisco8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.