Vulnerability record · CVE-2017-12231 · published 29 September 2017
CVE-2017-12231: Cisco IOS NAT ALG H.323 RAS packet handling denial of service
Cisco · Ios
Cisco IOS mishandles H.323 RAS messages processed by the NAT application layer gateway, allowing a crafted IPv4 packet to crash and reload the device. The NAT ALG for H.323 RAS is enabled by default, so affected devices are exposed without any special configuration. This is a remotely reachable availability flaw on core routing and edge platforms.
Description
A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to the improper translation of H.323 messages that use the Registration, Admission, and Status (RAS) protocol and are sent to an affected device via IPv4 packets. An attacker could exploit this vulnerability by sending a crafted H.323 RAS packet through an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition. This vulnerability affects Cisco devices that are configured to use an application layer gateway with NAT (NAT ALG) for H.323 RAS messages. By default, a NAT ALG is enabled for H.323 RAS messages. Cisco Bug IDs: CSCvc57217.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityRemote, unauthenticated, low-complexity denial of service on default-enabled NAT ALG functionality, with confirmed exploitation in CISA KEV, though impact is availability only.
What it is
Cisco IOS mishandles H.323 RAS messages processed by the NAT application layer gateway, allowing a crafted IPv4 packet to crash and reload the device. The NAT ALG for H.323 RAS is enabled by default, so affected devices are exposed without any special configuration. This is a remotely reachable availability flaw on core routing and edge platforms.
Impact
An unauthenticated remote attacker can force the affected device to crash and reload, causing a denial of service and a temporary loss of routing, NAT and any traffic traversing the device.
Attack surface
Reached over the network by sending a crafted H.323 RAS packet through a device that performs NAT ALG processing for H.323 RAS; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
CVE-2017-12231 is listed in CISA KEV with a 2022-03-03 addition date, indicating known exploitation in the wild; EPSS 30-day probability is about 7.1 percent (93.9th percentile). No ransomware campaign use is recorded.
What to do
- Apply the Cisco IOS software updates referenced in Cisco advisory cisco-sa-20170927-nat, prioritizing internet-facing and NAT edge devices.
- If patching cannot be done immediately, disable the H.323 RAS NAT ALG on affected devices where H.323 RAS translation is not required.
- Restrict inbound H.323 RAS traffic (UDP/TCP ports used by RAS) at network boundaries to trusted sources only.
- Review device configurations to identify systems running Cisco IOS 12.4 through 15.6 with NAT ALG enabled for H.323 RAS.
- Monitor for unexpected reloads and crash dumps on NAT edge devices as an indicator of attempted or successful exploitation.
Detection
- Alert on unexpected device reloads or crash/exception logs on Cisco IOS devices performing NAT ALG for H.323 RAS.
- Inspect inbound traffic for H.323 RAS messages directed at NAT edge devices from untrusted external sources.
- Correlate syslog or SNMP trap bursts showing interface and routing flaps immediately following H.323 RAS traffic.
- Audit configurations for NAT ALG H.323 RAS being enabled on devices that do not need it.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-12231 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/101039 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039449 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-nat | Vendor Advisory |
| http://www.securityfocus.com/bid/101039 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039449 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-nat | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-12231 | US Government Resource |
Track CVE-2017-12231 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-12231), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.