ZeroHour

CVE-2017-12235

KEVmass

Unauthenticated PN-DCP DoS (device reload) in Cisco IOS Industrial Ethernet Switches

CISA: Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability

CVSS 3.1
7.5 high
EPSS
7%p94
Published
()
KEV added
AI analysis

CVE-2017-12235 is a denial-of-service vulnerability in the PROFINET Discovery and Configuration Protocol (PN-DCP) implementation in Cisco IOS 12.2 through 15.6, caused by improper parsing of ingress PN-DCP Identify Request packets. An unauthenticated, remote attacker can trigger it by sending a crafted PN-DCP Identify Request packet to an affected device and then continuing to send normal PN-DCP Identify Request packets, causing the device to reload. A successful exploit has no confidentiality or integrity impact but forces the switch to reload, disrupting the industrial network it serves, and the attacker can repeat the sequence to prolong the outage. Only Cisco devices configured to process PROFINET messages are affected, and PROFINET has been enabled by default on base switch module and expansion-unit Ethernet ports since IOS 12.2(52)SE, so the exposure is concentrated among Cisco Industrial Ethernet switches deployed in manufacturing, energy, and similar OT environments. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating exploitation in the wild; no public proof-of-concept is known, ransomware use is unconfirmed, and EPSS estimates a ~7% probability of exploitation within 30 days.

What to do: Upgrade affected switches to a fixed Cisco IOS release per Cisco's advisory for bug CSCuz47179, as required by the CISA KEV entry, prioritizing switches reachable from untrusted networks or flat OT segments. As interim mitigation, segment or restrict access to switch ports that process PROFINET so only trusted industrial devices can reach them, and verify whether PROFINET is enabled by default on your IOS release (12.2(52)SE and later).

Affected
Cisco IOS (Cisco Industrial Ethernet Switches)12.2 through 15.6, on devices configured to process PROFINET messages; PROFINET is enabled by default on base switch module and expansion-unit Ethernet ports be
Estimated exposure
mass~100,000+ deployed Cisco industrial switches potentially affected (order-of-magnitude estimate); share reachable from enterprise or internet networks unknown — Cisco's Industrial Ethernet switch lines have been deployed at scale in manufacturing, energy, and transportation OT networks for more than a decade, and PROFINET is enabled by default on switch ports since IOS 12.2(52)SE, implying a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to the improper parsing of ingress PN-DCP Identify Request packets destined to an affected device. An attacker could exploit this vulnerability by sending a crafted PN-DCP Identify Request packet to an affected device and then continuing to send normal PN-DCP Identify Request packets to the device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. This vulnerability affects Cisco devices that are configured to process PROFINET messages. Beginning with Cisco IOS Software Release 12.2(52)SE, PROFINET is enabled by default on all the base switch module and expansion-unit Ethernet ports. Cisco Bug IDs: CSCuz47179.

CISA Known Exploited Vulnerability
Affected
Cisco IOS software
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
ios
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.