CVE-2017-12235
KEVmassUnauthenticated PN-DCP DoS (device reload) in Cisco IOS Industrial Ethernet Switches
CISA: Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability
CVE-2017-12235 is a denial-of-service vulnerability in the PROFINET Discovery and Configuration Protocol (PN-DCP) implementation in Cisco IOS 12.2 through 15.6, caused by improper parsing of ingress PN-DCP Identify Request packets. An unauthenticated, remote attacker can trigger it by sending a crafted PN-DCP Identify Request packet to an affected device and then continuing to send normal PN-DCP Identify Request packets, causing the device to reload. A successful exploit has no confidentiality or integrity impact but forces the switch to reload, disrupting the industrial network it serves, and the attacker can repeat the sequence to prolong the outage. Only Cisco devices configured to process PROFINET messages are affected, and PROFINET has been enabled by default on base switch module and expansion-unit Ethernet ports since IOS 12.2(52)SE, so the exposure is concentrated among Cisco Industrial Ethernet switches deployed in manufacturing, energy, and similar OT environments. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating exploitation in the wild; no public proof-of-concept is known, ransomware use is unconfirmed, and EPSS estimates a ~7% probability of exploitation within 30 days.
What to do: Upgrade affected switches to a fixed Cisco IOS release per Cisco's advisory for bug CSCuz47179, as required by the CISA KEV entry, prioritizing switches reachable from untrusted networks or flat OT segments. As interim mitigation, segment or restrict access to switch ports that process PROFINET so only trusted industrial devices can reach them, and verify whether PROFINET is enabled by default on your IOS release (12.2(52)SE and later).
| Cisco IOS (Cisco Industrial Ethernet Switches) | 12.2 through 15.6, on devices configured to process PROFINET messages; PROFINET is enabled by default on base switch module and expansion-unit Ethernet ports be |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to the improper parsing of ingress PN-DCP Identify Request packets destined to an affected device. An attacker could exploit this vulnerability by sending a crafted PN-DCP Identify Request packet to an affected device and then continuing to send normal PN-DCP Identify Request packets to the device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. This vulnerability affects Cisco devices that are configured to process PROFINET messages. Beginning with Cisco IOS Software Release 12.2(52)SE, PROFINET is enabled by default on all the base switch module and expansion-unit Ethernet ports. Cisco Bug IDs: CSCuz47179.
- Affected
- Cisco IOS software
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- ios
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.