CVE-2017-12235
published 2017-09-29CVE-2017-12235: A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an…
PriorityP277high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
7.13%
93.6th percentile
A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to the improper parsing of ingress PN-DCP Identify Request packets destined to an affected device. An attacker could exploit this vulnerability by sending a crafted PN-DCP Identify Request packet to an affected device and then continuing to send normal PN-DCP Identify Request packets to the device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. This vulnerability affects Cisco devices that are configured to process PROFINET messages. Beginning with Cisco IOS Software Release 12.2(52)SE, PROFINET is enabled by default on all the base switch module and expansion-unit Ethernet ports. Cisco Bug IDs: CSCuz47179.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | 12.2 – 15.6 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger condition requires two stages: first a crafted PN-DCP Identify Request packet, followed by normal PN-DCP Identify Request packets — monitor for device reloads correlated with PROFINET traffic bursts ↗
- →Scope detection to Cisco IOS devices configured to process PROFINET messages; PROFINET is enabled by default on all base switch module and expansion-unit Ethernet ports from IOS 12.2(52)SE onward ↗
- →Alert on unexpected device reloads on Cisco Industrial Ethernet switches receiving PN-DCP traffic — DoS manifests as a full device reload ↗
- ·PROFINET is enabled by default starting with IOS 12.2(52)SE on all base switch module and expansion-unit Ethernet ports, greatly expanding the attack surface without explicit administrator action ↗
- ·No workarounds exist for this vulnerability; patching is the only remediation ↗
- ·Affected IOS versions span a wide range: 12.2 through 15.6 — ensure version checks cover this entire range when scoping exposure ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vulncheck7.5HIGH
cisa7.5HIGH
vendor_cisco8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-83w7-v79x-495q: A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12
ghsa_unreviewed·2022-05-13
CVE-2017-12235 [HIGH] CWE-20 GHSA-83w7-v79x-495q: A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12
A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to the improper parsing of ingress PN-DCP Identify Request packets destined to an affected device. An attacker could exploit this vulnerability by sending a crafted PN-DCP Identify Request packet to an affected device and then continuing to send normal PN-DCP Identify Request packets to the device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. This vulnerability affects Cisco devices that are configured to process PROFINET messages.
VulnCheck
Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability
vulncheck·2017·CVSS 7.5
CVE-2017-12235 [HIGH] CWE-20 Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability
Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability
A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.
Affected: Cisco IOS Software
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-20170927-profinet.html
Remediation Due: 2022-03-24
CISA
Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability
cisa·2022-03-03·CVSS 7.5
CVE-2017-12235 [HIGH] CWE-20 Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability
Vulnerability: Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability
Affected: Cisco IOS software
A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-12235
Remediation Due Date: 2022-03-24
Cisco
Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial of Service Vulnerability
vendor_cisco·2017-09-27·CVSS 8.6
CVE-2017-12235 [HIGH] CWE-20 Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial of Service Vulnerability
Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial of Service Vulnerability
A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.
The vulnerability is due to the improper parsing of ingress PN-DCP Identify Request packets destined to an affected device. An attacker could exploit this vulnerability by sending a crafted PN-DCP Identify Request packet to an affected device and then continuing to send normal PN-DCP Identify Request packets to the device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS conditio
Cisco
Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-12235 Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial of Service Vulnerability
CVE-2017-12235: Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial of Service Vulnerability
A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to the improper parsing of ingress PN-DCP Identify Request packets destined to an affected device. An attacker could exploit this vulnerability by sending a crafted PN-DCP Identify Request packet to an affected device and then continuing to send normal PN-DCP Identify Request packets to the device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/101043http://www.securitytracker.com/id/1039451https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-profinethttp://www.securityfocus.com/bid/101043http://www.securitytracker.com/id/1039451https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-profinethttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-12235
2017-09-29
Published
2022-03-03
Added to CISA KEV
Exploited in the wild