CVE-2017-12238
published 2017-09-29CVE-2017-12238: A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an…
PriorityP276medium6.5CVSS 3.1
AVAACLPRNUINSUCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
2.03%
79.0th percentile
A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a denial of service (DoS) condition. The vulnerability is due to a memory management issue in the affected software. An attacker could exploit this vulnerability by creating a large number of VPLS-generated MAC entries in the MAC address table of an affected device. A successful exploit could allow the attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a DoS condition. This vulnerability affects Cisco Catalyst 6800 Series Switches that are running a vulnerable release of Cisco IOS Software and have a Cisco C6800-16P10G or C6800-16P10G-XL line card in use with Supervisor Engine 6T. To be vulnerable, the device must also be configured with VPLS and the C6800-16P10G or C6800-16P10G-XL line card needs to be the core-facing MPLS interfaces. Cisco Bug IDs: CSCva61927.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | 15.0 – 15.4 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation attempts by monitoring for abnormal growth of VPLS-generated MAC entries in the MAC address table on Cisco Catalyst 6800 Series devices ↗
- →Monitor for unexpected crashes or reloads of C6800-16P10G or C6800-16P10G-XL line cards, which may indicate active exploitation of this DoS vulnerability ↗
- ·Vulnerability is only exploitable when a C6800-16P10G or C6800-16P10G-XL line card is present AND acting as the core-facing MPLS interface with Supervisor Engine 6T ↗
- ·Only Cisco IOS versions 15.0 through 15.4 on Catalyst 6800 Series Switches are affected; IOS XE is not mentioned as in scope ↗
- ·The attacker must be adjacent (Layer 2 network proximity) — remote unauthenticated exploitation over the internet is not possible ↗
- ·No workarounds are available; only vendor software updates remediate this vulnerability ↗
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:N/I:N/A:P
vulncheck6.5MEDIUM
cisa6.5MEDIUM
vendor_cisco7.4HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability
cisa·2022-03-03·CVSS 6.5
CVE-2017-12238 [MEDIUM] CWE-399 Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability
Vulnerability: Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability
Affected: Cisco Catalyst 6800 Series Switches
A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a denial of service.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-12238
Remediation Due Date: 2022-03-24
Cisco
Cisco IOS Software for Cisco Catalyst 6800 Series Switches VPLS Denial of Service Vulnerability
vendor_cisco·2017-09-27·CVSS 7.4
CVE-2017-12238 [HIGH] CWE-399 Cisco IOS Software for Cisco Catalyst 6800 Series Switches VPLS Denial of Service Vulnerability
Cisco IOS Software for Cisco Catalyst 6800 Series Switches VPLS Denial of Service Vulnerability
A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS Software for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a denial of service (DoS) condition.
The vulnerability is due to a memory management issue in the affected software. An attacker could exploit this vulnerability by creating a large number of VPLS-generated MAC entries in the MAC address table of an affected device. A successful exploit could allow the attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a DoS condition.
Cisco has released software updates
Cisco
Cisco IOS Software for Cisco Catalyst 6800 Series Switches VPLS Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-12238 Cisco IOS Software for Cisco Catalyst 6800 Series Switches VPLS Denial of Service Vulnerability
CVE-2017-12238: Cisco IOS Software for Cisco Catalyst 6800 Series Switches VPLS Denial of Service Vulnerability
A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS Software for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a denial of service (DoS) condition. The vulnerability is due to a memory management issue in the affected software. An attacker could exploit this vulnerability by creating a large number of VPLS-generated MAC entries in the MAC address table of an affected device. A successful exploit could allow the attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a DoS condition. Cisco has released so
GHSA
GHSA-g8w4-jc9x-6qpc: A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15
ghsa_unreviewed·2022-05-13
CVE-2017-12238 [MEDIUM] GHSA-g8w4-jc9x-6qpc: A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15
A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a denial of service (DoS) condition. The vulnerability is due to a memory management issue in the affected software. An attacker could exploit this vulnerability by creating a large number of VPLS-generated MAC entries in the MAC address table of an affected device. A successful exploit could allow the attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a DoS condition. This vulnerability affects Cisco Catalyst 6800 Series Switches that are running a vulnerable release of Cisco IOS Software a
VulnCheck
Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability
vulncheck·2017·CVSS 6.5
CVE-2017-12238 [MEDIUM] CWE-399 Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability
Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability
A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a denial of service.
Affected: Cisco Catalyst 6800 Series Switches
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-03-24
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/101040http://www.securitytracker.com/id/1039453https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-vplshttp://www.securityfocus.com/bid/101040http://www.securitytracker.com/id/1039453https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-vplshttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-12238
2017-09-29
Published
2022-03-03
Added to CISA KEV
Exploited in the wild