ZeroHour

CVE-2017-12237

KEVmass

Unauthenticated IKEv2 Denial-of-Service in Cisco IOS and IOS XE

CISA: Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability

CVSS 3.1
7.5 high
EPSS
7%p94
Published
()
KEV added
AI analysis

A flaw in how Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 process Internet Key Exchange Version 2 (IKEv2) packets allows an unauthenticated, remote attacker to disrupt affected devices. The attacker sends specifically crafted IKEv2 packets to a device, which can drive CPU utilization very high, generate traceback messages, or force a reload, resulting in a denial-of-service condition with no impact to confidentiality or integrity (CVSS 3.1: 7.5, availability only). Any Cisco IOS or IOS XE device with ISAKMP enabled is vulnerable — no IKEv2-specific configuration is required — and this includes VPN gateways using LAN-to-LAN VPN, remote-access VPN (excluding SSL VPN), Dynamic Multipoint VPN (DMVPN), and FlexVPN, which are commonly placed at the network edge and reachable from the internet. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), confirming exploitation in the wild, and EPSS estimates a 7.1% probability of exploitation in the next 30 days (94th percentile); no public proof-of-concept is known.

What to do: Upgrade affected devices to fixed Cisco IOS/IOS XE releases per the vendor advisory (Bug CSCvc41277), as required by the CISA KEV listing. As interim mitigation, restrict IKE traffic (UDP 500/4500) to trusted peers with an ACL or disable ISAKMP on devices that do not use IKE/VPN features, and monitor for high CPU and unexpected reloads. Audit your estate for devices running IOS 15.0–15.6 or IOS XE 3.5–16.5 with ISAKMP enabled, prioritizing internet-facing VPN gateways.

Affected
Cisco IOS15.0 through 15.6 (devices with ISAKMP enabled)
Cisco IOS XE3.5 through 16.5 (devices with ISAKMP enabled)
Estimated exposure
masslikely hundreds of thousands of internet-reachable Cisco routers/VPN gateways with ISAKMP enabled — Cisco IOS/IOS XE is one of the most widely deployed network operating systems in enterprise routing and VPN edge deployments, and internet-wide scans of UDP/500 (ISAKMP/IKE) have repeatedly found hundreds of thousands of exposed devices, a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to how an affected device processes certain IKEv2 packets. An attacker could exploit this vulnerability by sending specific IKEv2 packets to an affected device to be processed. A successful exploit could allow the attacker to cause high CPU utilization, traceback messages, or a reload of the affected device that leads to a DoS condition. This vulnerability affects Cisco devices that have the Internet Security Association and Key Management Protocol (ISAKMP) enabled. Although only IKEv2 packets can be used to trigger this vulnerability, devices that are running Cisco IOS Software or Cisco IOS XE Software are vulnerable when ISAKMP is enabled. A device does not need to be configured with any IKEv2-specific features to be vulnerable. Many features use IKEv2, including different types of VPNs such as the following: LAN-to-LAN VPN; Remote-access VPN, excluding SSL VPN; Dynamic Multipoint VPN (DMVPN); and FlexVPN. Cisco Bug IDs: CSCvc41277.

CISA Known Exploited Vulnerability
Affected
Cisco IOS and IOS XE Software
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
ios, ios xe
Weakness
CWE-399
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.