cbcvebase.
CVE-2017-12240
published 2017-09-29

CVE-2017-12240: The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker…

PriorityP189critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
13.88%
96.1th percentile
The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system. The attacker could also cause an affected system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to a buffer overflow condition in the DHCP relay subsystem of the affected software. An attacker could exploit this vulnerability by sending a crafted DHCP Version 4 (DHCPv4) packet to an affected system. A successful exploit could allow the attacker to execute arbitrary code and gain full control of the affected system or cause the affected system to reload, resulting in a DoS condition. Cisco Bug IDs: CSCsm45390, CSCuw77959.

Affected

2 ranges
VendorProductVersion rangeFixed in
ciscoios12.2 – 15.6
ciscoios_and_ios_xe

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor for oversized DHCPv4 packets (e.g., 0x2000 byte DHCP discover messages) sent to DHCP relay agents, which may indicate exploitation of the heap buffer overflow (CVE-2018-0172 research variant).
  • Inspect DHCPv4 packets for malformed or crafted DHCP option 82 fields, including option 82 with invalid/oversized length values, as these are the attack vectors for the DHCP relay buffer overflow.
  • Look for DHCP relay agent crashes or unexpected reloads on Cisco IOS/IOS XE devices, which may indicate DoS exploitation of this vulnerability.
  • Flag DHCPv4 packets containing option 82 where the client-provided option 82 length exceeds the encapsulating agent-added option 82, as this triggers the bad pointer arithmetic access violation.
  • ·There are no workarounds available for this vulnerability; patching is the only remediation per Cisco's advisory.
  • ·The vulnerability affects Cisco IOS versions 12.2 through 15.6 and Cisco IOS XE Software. Cisco Bug IDs CSCsm45390 and CSCuw77959 track the affected code paths.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_cisco9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.