cbcvebase.
CVE-2017-12237
published 2017-09-29

CVE-2017-12237: A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow an…

PriorityP276high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
7.13%
93.6th percentile
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to how an affected device processes certain IKEv2 packets. An attacker could exploit this vulnerability by sending specific IKEv2 packets to an affected device to be processed. A successful exploit could allow the attacker to cause high CPU utilization, traceback messages, or a reload of the affected device that leads to a DoS condition. This vulnerability affects Cisco devices that have the Internet Security Association and Key Management Protocol (ISAKMP) enabled. Although only IKEv2 packets can be used to trigger this vulnerability, devices that are running Cisco IOS Software or Cisco IOS XE Software are vulnerable when ISAKMP is enabled. A device does not need to be configured with any IKEv2-specific features to be vulnerable. Many features use IKEv2, including different types of VPNs such as the following: LAN-to-LAN VPN; Remote-access VPN, excluding SSL VPN; Dynamic Multipoint VPN (DMVPN); and FlexVPN. Cisco Bug IDs: CSCvc41277.

Affected

3 ranges
VendorProductVersion rangeFixed in
ciscoios15.0 – 15.6
ciscoios_and_ios_xe
ciscoios_xe3.5.0e – 16.5

Detection & IOCsextracted from sources · hover to see the quote

  • Trigger condition: device must have ISAKMP enabled (not IKEv2-specific config required); exploit uses specific IKEv2 packets sent to the affected device
  • Monitor for sudden high CPU utilization, traceback messages, or unexpected reloads on Cisco IOS/IOS XE devices with ISAKMP enabled — these are observable DoS symptoms of successful exploitation
  • Scope detection to devices running Cisco IOS 15.0–15.6 or Cisco IOS XE 3.5–16.5 with ISAKMP enabled; IKEv2-based VPN features (LAN-to-LAN VPN, Remote-access VPN, DMVPN, FlexVPN) expand the attack surface
  • ·A device does NOT need IKEv2-specific configuration to be vulnerable — ISAKMP being enabled is sufficient; any feature using IKEv2 (LAN-to-LAN VPN, Remote-access VPN excluding SSL VPN, DMVPN, FlexVPN) implicitly exposes the attack surface
  • ·Cisco confirmed a workaround exists in addition to software updates; refer to the advisory for workaround details before patching
  • ·Two Cisco bug IDs are associated with this CVE: CSCvc41277 and CSCvc12306

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vulncheck7.5HIGH
cisa7.5HIGH
vendor_cisco8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.