CVE-2017-12240
KEVmassUnauthenticated RCE via DHCP Relay in Cisco IOS and IOS XE Software
CISA: Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability
CVE-2017-12240 is a buffer overflow (CWE-119/CWE-20) in the DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software. An unauthenticated, remote attacker can trigger it by sending a crafted DHCPv4 packet to a device running affected software with the DHCP relay subsystem processing untrusted packets. Successful exploitation allows arbitrary code execution and full control of the system, or alternatively forces a reload that causes a denial of service. Any organization running affected Cisco IOS or IOS XE releases on routers or Layer 3 switches, particularly edge or relay devices reachable over the network, is potentially affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03, indicating active exploitation in the wild, though no public proof-of-concept is known and ransomware use is unconfirmed; EPSS assigns a 13.9% probability of exploitation within 30 days (96th percentile).
What to do: Apply the fixed software releases per Cisco's advisory and CISA's required action (apply vendor updates), prioritizing internet-facing routers and devices with DHCP relay configured. As interim mitigation, disable DHCP relay where it is not needed and restrict access to DHCP ports (UDP 67/68) on affected devices using ACLs or upstream firewall rules. Check device inventory for IOS releases in the 12.2–15.6 range and IOS XE releases listed in the advisory, and verify whether DHCP relay is in use on each.
| Cisco IOS | 12.2 through 15.6 |
| Cisco IOS XE Software | affected releases as specified in the Cisco advisory (release numbers not enumerated in source data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system. The attacker could also cause an affected system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to a buffer overflow condition in the DHCP relay subsystem of the affected software. An attacker could exploit this vulnerability by sending a crafted DHCP Version 4 (DHCPv4) packet to an affected system. A successful exploit could allow the attacker to execute arbitrary code and gain full control of the affected system or cause the affected system to reload, resulting in a DoS condition. Cisco Bug IDs: CSCsm45390, CSCuw77959.
- Affected
- Cisco IOS and IOS XE Software
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- ios
- Weakness
- CWE-20, CWE-119
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H