ZeroHour

CVE-2017-12240

KEVmass

Unauthenticated RCE via DHCP Relay in Cisco IOS and IOS XE Software

CISA: Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
14%p96
Published
()
KEV added
AI analysis

CVE-2017-12240 is a buffer overflow (CWE-119/CWE-20) in the DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software. An unauthenticated, remote attacker can trigger it by sending a crafted DHCPv4 packet to a device running affected software with the DHCP relay subsystem processing untrusted packets. Successful exploitation allows arbitrary code execution and full control of the system, or alternatively forces a reload that causes a denial of service. Any organization running affected Cisco IOS or IOS XE releases on routers or Layer 3 switches, particularly edge or relay devices reachable over the network, is potentially affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03, indicating active exploitation in the wild, though no public proof-of-concept is known and ransomware use is unconfirmed; EPSS assigns a 13.9% probability of exploitation within 30 days (96th percentile).

What to do: Apply the fixed software releases per Cisco's advisory and CISA's required action (apply vendor updates), prioritizing internet-facing routers and devices with DHCP relay configured. As interim mitigation, disable DHCP relay where it is not needed and restrict access to DHCP ports (UDP 67/68) on affected devices using ACLs or upstream firewall rules. Check device inventory for IOS releases in the 12.2–15.6 range and IOS XE releases listed in the advisory, and verify whether DHCP relay is in use on each.

Affected
Cisco IOS12.2 through 15.6
Cisco IOS XE Softwareaffected releases as specified in the Cisco advisory (release numbers not enumerated in source data)
Estimated exposure
massseveral hundred thousand deployments plausibly affected (Cisco IOS/IOS XE installed base is in the millions; only the subset with DHCP relay enabled and… — Cisco IOS and IOS XE are deployed on millions of routers and switches worldwide, and public internet scans routinely show hundreds of thousands of Cisco devices exposed, but the DHCP relay requirement narrows the exploitable population.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system. The attacker could also cause an affected system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to a buffer overflow condition in the DHCP relay subsystem of the affected software. An attacker could exploit this vulnerability by sending a crafted DHCP Version 4 (DHCPv4) packet to an affected system. A successful exploit could allow the attacker to execute arbitrary code and gain full control of the affected system or cause the affected system to reload, resulting in a DoS condition. Cisco Bug IDs: CSCsm45390, CSCuw77959.

CISA Known Exploited Vulnerability
Affected
Cisco IOS and IOS XE Software
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
ios
Weakness
CWE-20, CWE-119
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news