Junglewise Threat Intelligence

CVE-2017-12232: Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability

CVE-2017-12232 · Severity: critical · CVSS 6.5 · Exploited in the wild · Published 2022-03-03

Technologies: Cisco IOS, Cisco Ios Software, Cisco IOS XE. Vendors: Cisco.

Executive brief

A vulnerability in Cisco IOS Software for Integrated Services Routers Generation 2 (ISR G2) allows an unauthenticated, adjacent attacker to cause a denial of service (DoS) by sending crafted Ethernet frames. The issue stems from a misclassification of Ethernet frames, which causes the affected device to reload.

Affected products

  • Cisco IOS 15.0 through 15.6
  • Cisco Integrated Services Routers Generation 2 (ISR G2) Routers

Timeline

  • 2017-09-27: disclosed: Original Cisco advisory date (from reference URL)
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats