ZeroHour

CVE-2017-12232

KEVmass

Unauthenticated Adjacent-Access DoS in Cisco IOS on ISR G2 Routers

CISA: Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability

CVSS 3.1
6.5 medium
EPSS
2%p81
Published
()
KEV added
AI analysis

Cisco IOS versions 15.0 through 15.6 running on Integrated Services Routers Generation 2 (ISR G2) routers contain a denial-of-service flaw caused by the misclassification of certain Ethernet frames. An unauthenticated attacker positioned adjacent to the device on the same Layer 2 segment can send a specially crafted Ethernet frame to the router, triggering a device reload. The attacker gains no data access - confidentiality and integrity are unaffected - but the forced reload halts routing at the site, producing an availability-only denial of service. Any organization operating ISR G2 routers on IOS 15.0-15.6 is affected, with risk concentrated on interfaces reachable from untrusted adjacent networks such as LAN, WAN-facing, or guest segments. The vulnerability is listed in CISA KEV (added 2022-03-03), indicating known exploitation in the wild; ransomware association is unknown, no public PoC is known, and EPSS puts the 30-day exploitation probability at 2.2% (81st percentile).

What to do: Per the CISA KEV required action, upgrade affected ISR G2 routers to a fixed Cisco IOS release in the 15.0-15.6 train per Cisco's advisory (bug ID CSCvc03809), confirming current versions with 'show version'. Where upgrades are delayed - many ISR G2 units are past standard software maintenance - limit untrusted devices' access to the Layer 2 segments attached to the router's interfaces and monitor syslog and crashinfo files for unexpected reloads. Treat any unexplained router reload on affected IOS versions as a possible exploitation indicator.

Affected
Cisco IOS (running on Integrated Services Routers Generation 2, ISR G2)15.0 through 15.6
Estimated exposure
massmillions of ISR G2 routers deployed, with hundreds of thousands of Cisco IOS devices visible in internet-wide scans — Cisco ISR G2 routers were among the most widely deployed enterprise branch-router platforms of the 2010s (an installed base likely in the millions), and public internet-wide scans have historically shown hundreds of thousands of Cisco IOS…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through 15.6 could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to a misclassification of Ethernet frames. An attacker could exploit this vulnerability by sending a crafted Ethernet frame to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvc03809.

CISA Known Exploited Vulnerability
Affected
Cisco IOS software
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
ios
Weakness
CWE-399
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.