← Vulnerability feed

Vulnerability record · CVE-2017-12231 · published 29 September 2017

CVE-2017-12231: Cisco IOS NAT ALG H.323 RAS packet handling denial of service

Cisco · Ios

Cisco IOS mishandles H.323 RAS messages processed by the NAT application layer gateway, allowing a crafted IPv4 packet to crash and reload the device. The NAT ALG for H.323 RAS is enabled by default, so affected devices are exposed without any special configuration. This is a remotely reachable availability flaw on core routing and edge platforms.

7.5 CVSS 3.1 High CISA KEV since 3 Mar 2022 EPSS 7.1% · top 6.0% CWE-399 · CWE-399
7.5CVSS 3.1 base score, v2 7.8
7.1%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to the improper translation of H.323 messages that use the Registration, Admission, and Status (RAS) protocol and are sent to an affected device via IPv4 packets. An attacker could exploit this vulnerability by sending a crafted H.323 RAS packet through an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition. This vulnerability affects Cisco devices that are configured to use an application layer gateway with NAT (NAT ALG) for H.323 RAS messages. By default, a NAT ALG is enabled for H.323 RAS messages. Cisco Bug IDs: CSCvc57217.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityRemote, unauthenticated, low-complexity denial of service on default-enabled NAT ALG functionality, with confirmed exploitation in CISA KEV, though impact is availability only.

What it is

Cisco IOS mishandles H.323 RAS messages processed by the NAT application layer gateway, allowing a crafted IPv4 packet to crash and reload the device. The NAT ALG for H.323 RAS is enabled by default, so affected devices are exposed without any special configuration. This is a remotely reachable availability flaw on core routing and edge platforms.

Impact

An unauthenticated remote attacker can force the affected device to crash and reload, causing a denial of service and a temporary loss of routing, NAT and any traffic traversing the device.

Attack surface

Reached over the network by sending a crafted H.323 RAS packet through a device that performs NAT ALG processing for H.323 RAS; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

CVE-2017-12231 is listed in CISA KEV with a 2022-03-03 addition date, indicating known exploitation in the wild; EPSS 30-day probability is about 7.1 percent (93.9th percentile). No ransomware campaign use is recorded.

What to do

  • Apply the Cisco IOS software updates referenced in Cisco advisory cisco-sa-20170927-nat, prioritizing internet-facing and NAT edge devices.
  • If patching cannot be done immediately, disable the H.323 RAS NAT ALG on affected devices where H.323 RAS translation is not required.
  • Restrict inbound H.323 RAS traffic (UDP/TCP ports used by RAS) at network boundaries to trusted sources only.
  • Review device configurations to identify systems running Cisco IOS 12.4 through 15.6 with NAT ALG enabled for H.323 RAS.
  • Monitor for unexpected reloads and crash dumps on NAT edge devices as an indicator of attempted or successful exploitation.

Detection

  • Alert on unexpected device reloads or crash/exception logs on Cisco IOS devices performing NAT ALG for H.323 RAS.
  • Inspect inbound traffic for H.323 RAS messages directed at NAT edge devices from untrusted external sources.
  • Correlate syslog or SNMP trap bursts showing interface and routing flaps immediately following H.323 RAS traffic.
  • Audit configurations for NAT ALG H.323 RAS being enabled on devices that do not need it.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-12231 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-12231 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-0171Cisco IOS Smart Install improper input validation allows remote code executionCisco IOS and IOS XE Smart Install fails to properly validate packet data, so a crafted Smart Install message sent to TCP port 4786 can overflow a bu…KEVEPSS 99%analysed9.8CVE-2017-12240Cisco IOS and IOS XE DHCP Relay Buffer Overflow RCEThe DHCP relay subsystem in Cisco IOS 12.2 through 15.6 and Cisco IOS XE contains a buffer overflow caused by improper input validation of DHCPv4 pac…KEVEPSS 14%analysed9.8CVE-2017-3881Cisco IOS/IOS XE CMP Telnet Option Handling RCECisco IOS and IOS XE fail to restrict CMP-specific Telnet options to internal cluster communications and mishandle malformed CMP Telnet options, so a…KEVEPSS 99%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.8CVE-2017-6736Cisco IOS and IOS XE SNMP buffer overflow remote code executionThe SNMP subsystem in Cisco IOS and IOS XE contains a buffer overflow that can be triggered by a crafted SNMP packet sent over IPv4 or IPv6. It affec…KEVEPSS 70%analysed8.8CVE-2017-6737Cisco IOS and IOS XE SNMP Buffer Overflow RCECisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMPv1, v2c, and v3. An authenticated remote attacker who know…KEVEPSS 45%analysed8.8CVE-2017-6738Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionThe SNMP subsystem in Cisco IOS and IOS XE Software contains a buffer overflow that affects SNMP versions 1, 2c, and 3. An authenticated remote attac…KEVEPSS 11%analysed8.8CVE-2017-6739Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionCisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMP versions 1, 2c, and 3. A remote attacker who knows the SN…KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-2017-12231), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.