Junglewise Threat Intelligence

CVE-2017-12319: Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability

CVE-2017-12319 · Severity: critical · CVSS 5.9 · Exploited in the wild · Published 2022-03-03

Technologies: Cisco IOS XE Software, Cisco IOS XE. Vendors: Cisco.

Executive brief

A vulnerability in the BGP implementation for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) or corrupt the BGP routing table. The issue stems from a miscalculation of the IP address length field when processing BGP Inclusive Multicast Ethernet Tag Route or MAC/IP Advertisement Route update packets.

Affected products

  • Cisco IOS XE prior to 16.3

Timeline

  • 2017-11-03: disclosed: Initial Cisco advisory publication
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats