7.8
CVSSv2

CVE-2017-12234

Published: 29/09/2017 Updated: 09/10/2019
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 up to and including 15.6 could allow an unauthenticated, remote malicious user to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of crafted CIP packets destined to an affected device. An attacker could exploit these vulnerabilities by sending crafted CIP packets to be processed by an affected device. A successful exploit could allow the malicious user to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvc43709.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios 15.3\\(3\\)jpb2

cisco ios 12.4\\(25e\\)jao3a

cisco ios 15.3\\(3\\)jpb

cisco ios 15.2\\(2\\)eb2

cisco ios 15.3\\(3\\)je1

cisco ios 15.6\\(2\\)s3

cisco ios 15.3\\(3\\)jc7

cisco ios 15.6\\(2\\)s0a

cisco ios 15.1\\(2\\)sg7a

cisco ios 15.3\\(3\\)jnp2

cisco ios 12.4\\(25e\\)jap9

cisco ios 15.6\\(1\\)s1a

cisco ios 15.2\\(2\\)e5b

cisco ios 15.3\\(3\\)jca7

cisco ios 15.3\\(3\\)jnc4

cisco ios 15.2\\(2\\)eb

cisco ios 15.2\\(4\\)ec1

cisco ios 15.6\\(2\\)sp2a

cisco ios 15.2\\(2\\)e3

cisco ios 15.6\\(2\\)sp1c

cisco ios 15.2\\(4\\)ec

cisco ios 15.6\\(2\\)s2

cisco ios 15.2\\(4\\)ec2

cisco ios 12.4\\(25e\\)jap1n

cisco ios 15.6\\(2\\)sp1b

cisco ios 15.2\\(2\\)eb1

cisco ios 15.3\\(3\\)jc51

cisco ios 15.2\\(5\\)e

cisco ios 15.2\\(5\\)e2a

cisco ios 15.3\\(3\\)jpc3

cisco ios 15.3\\(3\\)jda3

cisco ios 15.3\\(3\\)jbb6a

cisco ios 15.2\\(5a\\)e1

cisco ios 15.2\\(3\\)ex

cisco ios 15.3\\(3\\)jnd2

cisco ios 15.0\\(2\\)sqd7

cisco ios 15.2\\(5\\)e2b

cisco ios 15.3\\(3\\)jc50

cisco ios 12.4\\(25e\\)jao20s

Vendor Advisories

Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition The vulnerabilities are due to the improper parsing of crafted CIP packets destined to an affect ...