ZeroHour

CVE-2017-12231

KEVmass

Unauthenticated DoS in Cisco IOS NAT via crafted H.323 RAS packets

CISA: Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability

CVSS 3.1
7.5 high
EPSS
7%p94
Published
()
KEV added
AI analysis

CVE-2017-12231 is a denial-of-service flaw in the Network Address Translation (NAT) application layer gateway of Cisco IOS 12.4 through 15.6, caused by improper translation of H.323 Registration, Admission, and Status (RAS) messages. An unauthenticated, remote attacker can exploit it by sending a crafted H.323 RAS packet in IPv4 traffic through an affected device that is performing NAT. A successful attack crashes the device, forcing a reload and interrupting traffic, with no impact on confidentiality or integrity (CVSS 3.1: 7.5 high, availability only). Any Cisco device running affected IOS releases with NAT and the H.323 NAT ALG is exposed, and the ALG is enabled by default, so most NAT-configured IOS devices are potentially affected. The flaw is being actively exploited: it was added to the CISA Known Exploited Vulnerabilities catalog on 2022-03-03, though no public proof-of-concept is known.

What to do: Upgrade affected devices to a fixed Cisco IOS release per Cisco's security advisory (Cisco Bug ID CSCvc57217), as required by the CISA KEV catalog. Where upgrading is not immediately possible, disable the H.323 NAT ALG on affected NAT configurations (per vendor instructions) if H.323/VoIP traffic does not need to traverse that NAT, and prioritize internet-facing or edge routers performing NAT for exposure review. Check device configurations for NAT with the H.323 ALG enabled (default) to identify which devices need remediation.

Affected
Cisco IOS12.4 through 15.6 (devices using NAT with the H.323 NAT ALG, which is enabled by default)
Estimated exposure
masson the order of hundreds of thousands of Cisco IOS devices, though the affected subset performing NAT for H.323 traffic is not precisely known (estimate) — Cisco IOS is one of the most widely deployed router/switch platforms, with public internet scans historically showing hundreds of thousands of IOS devices reachable online, and the vulnerable H.323 NAT ALG is enabled by default on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to the improper translation of H.323 messages that use the Registration, Admission, and Status (RAS) protocol and are sent to an affected device via IPv4 packets. An attacker could exploit this vulnerability by sending a crafted H.323 RAS packet through an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition. This vulnerability affects Cisco devices that are configured to use an application layer gateway with NAT (NAT ALG) for H.323 RAS messages. By default, a NAT ALG is enabled for H.323 RAS messages. Cisco Bug IDs: CSCvc57217.

CISA Known Exploited Vulnerability
Affected
Cisco IOS software
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
ios
Weakness
CWE-399
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.