Junglewise Threat Intelligence

CVE-2017-12240: Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability

CVE-2017-12240 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-03

Technologies: Cisco IOS, Cisco IOS XE Software, Cisco IOS XE, Cisco IOS XR. Vendors: Cisco.

Executive brief

A buffer overflow vulnerability in the DHCP relay subsystem of Cisco IOS and IOS XE Software allows an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service. The flaw is triggered by sending crafted DHCPv4 packets to an affected device.

Affected products

  • Cisco IOS 12.2 through 15.6
  • Cisco IOS XE

Timeline

  • 2017-09-27: advisory: Initial Cisco advisory published
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats