Junglewise Threat Intelligence

CVE-2017-12231: Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability

CVE-2017-12231 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2022-03-03

Technologies: Cisco IOS, Cisco Ios Software, Cisco IOS XE. Vendors: Cisco.

Executive brief

A vulnerability in Cisco IOS NAT implementation allows remote attackers to cause a denial of service (device crash and reload) via crafted H.323 RAS packets. The issue stems from improper translation of H.323 messages using the Registration, Admission, and Status (RAS) protocol when NAT ALG is enabled.

Affected products

  • Cisco IOS 12.4 through 15.6

Timeline

  • 2017-09-27: disclosed: Initial Cisco advisory publication
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats