cbcvebase.
CVE-2017-12235
published 2017-09-29

CVE-2017-12235: A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an…

PriorityP277high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
7.13%
93.6th percentile
A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to the improper parsing of ingress PN-DCP Identify Request packets destined to an affected device. An attacker could exploit this vulnerability by sending a crafted PN-DCP Identify Request packet to an affected device and then continuing to send normal PN-DCP Identify Request packets to the device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. This vulnerability affects Cisco devices that are configured to process PROFINET messages. Beginning with Cisco IOS Software Release 12.2(52)SE, PROFINET is enabled by default on all the base switch module and expansion-unit Ethernet ports. Cisco Bug IDs: CSCuz47179.

Affected

2 ranges
VendorProductVersion rangeFixed in
ciscoios
ciscoios12.2 – 15.6

Detection & IOCsextracted from sources · hover to see the quote

  • Trigger condition requires two stages: first a crafted PN-DCP Identify Request packet, followed by normal PN-DCP Identify Request packets — monitor for device reloads correlated with PROFINET traffic bursts
  • Scope detection to Cisco IOS devices configured to process PROFINET messages; PROFINET is enabled by default on all base switch module and expansion-unit Ethernet ports from IOS 12.2(52)SE onward
  • Alert on unexpected device reloads on Cisco Industrial Ethernet switches receiving PN-DCP traffic — DoS manifests as a full device reload
  • ·PROFINET is enabled by default starting with IOS 12.2(52)SE on all base switch module and expansion-unit Ethernet ports, greatly expanding the attack surface without explicit administrator action
  • ·No workarounds exist for this vulnerability; patching is the only remediation
  • ·Affected IOS versions span a wide range: 12.2 through 15.6 — ensure version checks cover this entire range when scoping exposure

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vulncheck7.5HIGH
cisa7.5HIGH
vendor_cisco8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.