Junglewise Threat Intelligence

CVE-2017-12234: Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability

CVE-2017-12234 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2022-03-03

Technologies: Cisco IOS, Cisco Ios Software, Cisco IOS XE. Vendors: Cisco.

Executive brief

A vulnerability in the Common Industrial Protocol (CIP) feature of Cisco IOS allows an unauthenticated, remote attacker to cause a denial of service (DoS) by sending crafted CIP packets. The issue stems from improper parsing of these packets, which triggers a device reload.

Affected products

  • Cisco IOS 12.4 through 15.6

Timeline

  • 2017-09-27: advisory: Original Cisco security advisory published
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-03: disclosed: NVD publication date

Related threats