Junglewise Threat Intelligence

CVE-2017-12237: Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability

CVE-2017-12237 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2022-03-03

Technologies: Cisco IOS, Cisco IOS XE Software, Cisco IOS XE, Cisco IOS XR. Vendors: Cisco.

Executive brief

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS and IOS XE could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The issue is triggered by processing specific IKEv2 packets, leading to high CPU utilization, traceback messages, or a device reload.

Affected products

  • Cisco IOS 15.0 through 15.6
  • Cisco IOS XE 3.5 through 16.5

Timeline

  • 2017-09-27: disclosed: Original Cisco advisory date (from reference URL)
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats