Junglewise Threat Intelligence

CVE-2017-12238: Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability

CVE-2017-12238 · Severity: critical · CVSS 6.5 · Exploited in the wild · Published 2022-03-03

Technologies: Cisco IOS. Vendors: Cisco.

Executive brief

A memory management vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS could allow an unauthenticated, adjacent attacker to cause a denial of service. By generating a large number of VPLS MAC entries, an attacker can cause C6800-16P10G or C6800-16P10G-XL line cards to crash on Catalyst 6800 Series Switches equipped with Supervisor Engine 6T.

Affected products

  • Cisco IOS 15.0 through 15.4
  • Cisco Catalyst 6800 Series Switches
  • Cisco C6800-16P10G Line Card
  • Cisco C6800-16P10G-XL Line Card

Timeline

  • 2017-09-27: disclosed: Original Cisco advisory date based on URL and reference data
  • 2022-03-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-03: exploited: Vulnerability confirmed as exploited in the wild per CISA KEV entry