ZeroHour

CVE-2017-12238

KEVniche

VPLS Denial-of-Service in Cisco Catalyst 6800 Series Switches

CISA: Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability

CVSS 3.1
6.5 medium
EPSS
2%p80
Published
()
KEV added
AI analysis

CVE-2017-12238 is a memory management flaw (CWE-399) in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 on Cisco Catalyst 6800 Series Switches. An unauthenticated, adjacent attacker can trigger it by creating a large number of VPLS-generated MAC entries in the device's MAC address table, causing memory mismanagement that crashes a C6800-16P10G or C6800-16P10G-XL line card. The impact is a denial of service: traffic handled by the crashed line card is interrupted, with no confidentiality or integrity impact (CVSS 3.1 base 6.5, availability-focused). Only deployments running Cisco IOS 15.0-15.4 on a Catalyst 6800 with Supervisor Engine 6T, a C6800-16P10G or C6800-16P10G-XL line card, VPLS configured, and that line card serving as the core-facing MPLS interface are affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating known in-the-wild exploitation, though no public proof-of-concept is known and ransomware use is unconfirmed.

What to do: Inventory Catalyst 6800 chassis for C6800-16P10G or C6800-16P10G-XL line cards on Supervisor Engine 6T with VPLS configured and the line card as the core-facing MPLS interface, and upgrade Cisco IOS to a fixed release per Cisco's advisory (Bug ID CSCva61927), since all 15.0-15.4 trains listed are vulnerable. Because the flaw is on CISA's KEV list, prioritize patching; interim mitigations include restricting adjacent access to the MPLS core-facing interfaces and monitoring for abnormal MAC address table growth on VPLS instances.

Affected
Cisco Catalyst 6800 Series Switches (with C6800-16P10G or C6800-16P10G-XL line card and Supervisor Engine 6T, VPLS configured,Cisco IOS 15.0 through 15.4
Cisco IOS15.0 through 15.4 (as used on Catalyst 6800 Series Switches)
Estimated exposure
nicheNo basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a denial of service (DoS) condition. The vulnerability is due to a memory management issue in the affected software. An attacker could exploit this vulnerability by creating a large number of VPLS-generated MAC entries in the MAC address table of an affected device. A successful exploit could allow the attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a DoS condition. This vulnerability affects Cisco Catalyst 6800 Series Switches that are running a vulnerable release of Cisco IOS Software and have a Cisco C6800-16P10G or C6800-16P10G-XL line card in use with Supervisor Engine 6T. To be vulnerable, the device must also be configured with VPLS and the C6800-16P10G or C6800-16P10G-XL line card needs to be the core-facing MPLS interfaces. Cisco Bug IDs: CSCva61927.

CISA Known Exploited Vulnerability
Affected
Cisco Catalyst 6800 Series Switches
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
ios
Weakness
CWE-399
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.