ZeroHour

CVE-2017-12234

KEVlarge

Unauthenticated CIP Packet Parsing DoS in Cisco IOS 12.4–15.6

CISA: Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability

CVSS 3.1
7.5 high
EPSS
7%p94
Published
()
KEV added
AI analysis

Cisco IOS 12.4 through 15.6 contains flaws in the parsing of Common Industrial Protocol (CIP) packets that allow an unauthenticated, remote attacker to crash an affected device. The improper input handling (CWE-20) is triggered when crafted CIP packets destined to the device are processed by its CIP implementation, requiring no credentials or user interaction. A successful exploit causes the device to reload, so the attacker gains only an availability impact — a denial-of-service condition with no confidentiality or integrity compromise. Any Cisco IOS device on the affected trains that processes CIP traffic, typically in industrial/OT network deployments, is exposed. The vulnerability was added to CISA's Known Exploited Vulnerability catalog on 2022-03-03, confirming exploitation in the wild (ransomware use unknown); no public proof-of-concept is known and EPSS puts the 30-day exploitation probability at 7.1% (94th percentile).

What to do: Upgrade affected devices to a fixed IOS release per Cisco's advisory for Bug ID CSCvc43709 — this is also the CISA KEV required action — and confirm the running software train with 'show version'. Inventory which devices actually process CIP/EtherNet/IP traffic, since only those are exploitable, and in the interim restrict untrusted remote access to them; note that the vendor lists no workaround that fully addresses the flaw.

Affected
Cisco IOS12.4 through 15.6
Estimated exposure
large≈ tens of thousands of devices (a subset of the hundreds of thousands of deployed Cisco IOS systems) — Cisco IOS is among the most widely deployed network operating systems, with hundreds of thousands of routers and switches visible in enterprise networks and public internet scans, but the flaw is only exploitable on devices whose CIP…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of crafted CIP packets destined to an affected device. An attacker could exploit these vulnerabilities by sending crafted CIP packets to be processed by an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvc43709.

CISA Known Exploited Vulnerability
Affected
Cisco IOS software
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
ios
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.