← Vulnerability feed

Vulnerability record · CVE-2017-12219 · published 21 September 2017

CVE-2017-12219: Cisco spa 301 firmware vulnerability

Cisco · Spa 301 Firmware

A vulnerability in the handling of IP fragments for the Cisco Small Business SPA300, SPA500, and SPA51x Series IP Phones could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to the inability to handle many large IP fragments for reassembly in a short duration. An attacker could exploit this vulnerability by sending a crafted stream of IP fragments to the targeted device. An exploit could allow the attacker to cause a DoS condition when the device unexpectedly reloads. Cisco Bug IDs: CSCve82586.

7.5 CVSS 3.0 High EPSS 2.7% · top 14.9% CWE-399 · CWE-399
7.5CVSS 3.0 base score, v2 7.8
2.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
11Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the handling of IP fragments for the Cisco Small Business SPA300, SPA500, and SPA51x Series IP Phones could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to the inability to handle many large IP fragments for reassembly in a short duration. An attacker could exploit this vulnerability by sending a crafted stream of IP fragments to the targeted device. An exploit could allow the attacker to cause a DoS condition when the device unexpectedly reloads. Cisco Bug IDs: CSCve82586.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-12219 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-20450Cisco spa 301 firmware classic buffer overflow vulnerabilityMultiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series…EPSS 7.2%9.8CVE-2024-20454Cisco spa 301 firmware classic buffer overflow vulnerabilityMultiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series…EPSS 6.6%7.5CVE-2024-20451Cisco spa 301 firmware classic buffer overflow vulnerabilityMultiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series…EPSS 0.75%7.5CVE-2017-12260Cisco spa 501g firmware memory buffer overflow vulnerabilityA vulnerability in the implementation of Session Initiation Protocol (SIP) functionality in Cisco Small Business SPA50x, SPA51x, and SPA52x Series IP…EPSS 2.3%8.8CVE-2010-0806Microsoft Internet Explorer Peer Objects use-after-free allows remote code executionInternet Explorer 6, 6 SP1 and 7 contain a use-after-free in the Peer Objects component (iepeers.dll), where an object is accessed after deletion, le…KEVEPSS 82%analysed5.9CVE-2018-0180Cisco IOS Login Block feature denial-of-service via crafted login attemptsMultiple flaws in the Login Enhancements (Login Block) feature of Cisco IOS Software let an unauthenticated remote attacker trigger a reload of the d…KEVEPSS 4.9%analysed5.9CVE-2018-0179Cisco IOS Login Block feature denial-of-service flawMultiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software let an unauthenticated, remote attacker trigger a relo…KEVEPSS 4.9%analysed6.3CVE-2018-0161Cisco IOS SNMP GET Request Causes Device RestartCisco IOS Software on certain Catalyst switches mishandles SNMP read requests for the ciscoFlashMIB object ID, causing a SYS-3-CPUHOG condition that …KEVEPSS 4.1%analysed

Source: NIST National Vulnerability Database (record CVE-2017-12219), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.