CVE-2017-12237
KEVmassUnauthenticated IKEv2 Denial-of-Service in Cisco IOS and IOS XE
CISA: Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability
A flaw in how Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 process Internet Key Exchange Version 2 (IKEv2) packets allows an unauthenticated, remote attacker to disrupt affected devices. The attacker sends specifically crafted IKEv2 packets to a device, which can drive CPU utilization very high, generate traceback messages, or force a reload, resulting in a denial-of-service condition with no impact to confidentiality or integrity (CVSS 3.1: 7.5, availability only). Any Cisco IOS or IOS XE device with ISAKMP enabled is vulnerable — no IKEv2-specific configuration is required — and this includes VPN gateways using LAN-to-LAN VPN, remote-access VPN (excluding SSL VPN), Dynamic Multipoint VPN (DMVPN), and FlexVPN, which are commonly placed at the network edge and reachable from the internet. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), confirming exploitation in the wild, and EPSS estimates a 7.1% probability of exploitation in the next 30 days (94th percentile); no public proof-of-concept is known.
What to do: Upgrade affected devices to fixed Cisco IOS/IOS XE releases per the vendor advisory (Bug CSCvc41277), as required by the CISA KEV listing. As interim mitigation, restrict IKE traffic (UDP 500/4500) to trusted peers with an ACL or disable ISAKMP on devices that do not use IKE/VPN features, and monitor for high CPU and unexpected reloads. Audit your estate for devices running IOS 15.0–15.6 or IOS XE 3.5–16.5 with ISAKMP enabled, prioritizing internet-facing VPN gateways.
| Cisco IOS | 15.0 through 15.6 (devices with ISAKMP enabled) |
| Cisco IOS XE | 3.5 through 16.5 (devices with ISAKMP enabled) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to how an affected device processes certain IKEv2 packets. An attacker could exploit this vulnerability by sending specific IKEv2 packets to an affected device to be processed. A successful exploit could allow the attacker to cause high CPU utilization, traceback messages, or a reload of the affected device that leads to a DoS condition. This vulnerability affects Cisco devices that have the Internet Security Association and Key Management Protocol (ISAKMP) enabled. Although only IKEv2 packets can be used to trigger this vulnerability, devices that are running Cisco IOS Software or Cisco IOS XE Software are vulnerable when ISAKMP is enabled. A device does not need to be configured with any IKEv2-specific features to be vulnerable. Many features use IKEv2, including different types of VPNs such as the following: LAN-to-LAN VPN; Remote-access VPN, excluding SSL VPN; Dynamic Multipoint VPN (DMVPN); and FlexVPN. Cisco Bug IDs: CSCvc41277.
- Affected
- Cisco IOS and IOS XE Software
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- ios, ios xe
- Weakness
- CWE-399
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.