CVE-2017-12240 KEV
Patch first
On CISA KEV — known exploited in the wild, due 2022-03-24.
Description
The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system. The attacker could also cause an affected system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to a buffer overflow condition in the DHCP relay subsystem of the affected software. An attacker could exploit this vulnerability by sending a crafted DHCP Version 4 (DHCPv4) packet to an affected system. A successful exploit could allow the attacker to execute arbitrary code and gain full control of the affected system or cause the affected system to reload, resulting in a DoS condition. Cisco Bug IDs: CSCsm45390, CSCuw77959.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 13.77% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | yes — remediate by 2022-03-24 |
| Public exploit | none known |
| Published | 2017-09-29 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability |
|---|---|
| Added | 2022-03-03 |
| Due | 2022-03-24 |
| Vendor / product | Cisco / IOS and IOS XE Software |
| Ransomware use | none reported |
Affected (40)
| Vendor | Product |
|---|---|
| cisco | 1000 integrated services router |
| cisco | 1100 integrated services router |
| cisco | 1100-4g integrated services router |
| cisco | 1100-4gltegb integrated services router |
| cisco | 1100-4gltena integrated services router |
| cisco | 1100-4p integrated services router |
| cisco | 1100-6g integrated services router |
| cisco | 1100-8p integrated services router |
| cisco | 1100-lte integrated services router |
| cisco | 1101 integrated services router |
| cisco | 1101-4p integrated services router |
| cisco | 1109 integrated services router |
| cisco | 1109-2p integrated services router |
| cisco | 1109-4p integrated services router |
| cisco | 1111x integrated services router |
| cisco | 1111x-8p integrated services router |
| cisco | 111x integrated services router |
| cisco | 1120 integrated services router |
| cisco | 1131 integrated services router |
| cisco | 1160 integrated services router |
| cisco | 1801 integrated service router |
| cisco | 1802 integrated service router |
| cisco | 1803 integrated service router |
| cisco | 1811 integrated service router |
| cisco | 1812 integrated service router |
| cisco | 1841 integrated service router |
| cisco | 1861 integrated service router |
| cisco | 1905 integrated services router |
| cisco | 1906c integrated services router |
| cisco | 1921 integrated services router |
| cisco | 1941 integrated services router |
| cisco | 1941w integrated services router |
| cisco | 4000 integrated services router |
| cisco | 422 integrated services router |
| cisco | 4221 integrated services router |
| cisco | 8101-32fh |
| cisco | 8101-32h |
| cisco | 8102-64h |
| cisco | 8201 |
| cisco | ios |
References
- http://www.securityfocus.com/bid/101034
- http://www.securitytracker.com/id/1039445
- https://quickview.cloudapps.cisco.com/quickview/bug/CSCsm45390
- https://quickview.cloudapps.cisco.com/quickview/bug/CSCuw77959
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-dhcp
- http://www.securityfocus.com/bid/101034
- http://www.securitytracker.com/id/1039445
- https://quickview.cloudapps.cisco.com/quickview/bug/CSCsm45390
- https://quickview.cloudapps.cisco.com/quickview/bug/CSCuw77959
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-dhcp
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-12240
→ the Explorer · watch your stack · NVD