Executive brief
A vulnerability in the Common Industrial Protocol (CIP) feature of Cisco IOS allows an unauthenticated, remote attacker to cause a denial of service (DoS) by sending crafted CIP packets. The issue stems from improper parsing of these packets, which triggers a device reload.
Affected products
- Cisco IOS 12.4 through 15.6
Timeline
- 2017-09-27: advisory: Original Cisco security advisory published
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-03: disclosed: NVD publication date