Vulnerability record · CVE-2017-12232 · published 29 September 2017
CVE-2017-12232: Cisco IOS ISR G2 Ethernet frame misclassification denial of service
Cisco · Ios
Cisco IOS 15.0 through 15.6 on Integrated Services Routers Generation 2 (ISR G2) misclassifies certain Ethernet frames, allowing an adjacent, unauthenticated attacker to trigger a device reload. The result is a denial-of-service condition on the affected router, which can disrupt all traffic it forwards.
Description
A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through 15.6 could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to a misclassification of Ethernet frames. An attacker could exploit this vulnerability by sending a crafted Ethernet frame to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvc03809.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityThe flaw is remotely triggerable by an unauthenticated adjacent attacker, causes full device reload, and is listed in CISA KEV as exploited in the wild, though impact is limited to availability.
What it is
Cisco IOS 15.0 through 15.6 on Integrated Services Routers Generation 2 (ISR G2) misclassifies certain Ethernet frames, allowing an adjacent, unauthenticated attacker to trigger a device reload. The result is a denial-of-service condition on the affected router, which can disrupt all traffic it forwards.
Impact
An attacker can force the affected router to reload, causing a denial of service. There is no reported confidentiality or integrity impact; only availability is affected.
Attack surface
The flaw is reached by sending a crafted Ethernet frame to the device, so the attacker must be on the same adjacent Layer 2 segment. No authentication or user interaction is required per the CVSS vector (AV:A/AC:L/PR:N/UI:N).
Exploitation
The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating exploitation in the wild; EPSS 30-day probability is about 2.2 percent (81st percentile). No public exploit code or ransomware use is documented in this record.
What to do
- Apply the Cisco IOS updates referenced in Cisco Security Advisory cisco-sa-20170927-rbip-dos, prioritizing ISR G2 devices running IOS 15.0 through 15.6.
- Restrict Layer 2 adjacency to the router: enforce port security, disable unused switch ports, and segment management and user VLANs.
- Apply infrastructure ACLs and control-plane protections where feasible to limit which hosts can send traffic directly to the router.
- Monitor Cisco advisories for updated fixed releases and track the CISA KEV remediation due date (2022-03-24) for compliance reporting.
Detection
- Alert on unexpected router reloads or syslog messages indicating crash or reload events on ISR G2 devices running IOS 15.0 through 15.6.
- Monitor for sudden loss of adjacency or interface resets on segments directly connected to affected routers.
- Correlate router restart events with unusual Layer 2 traffic or new hosts appearing on adjacent segments.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-12232 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/101044 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039452 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-rbip-dos | Vendor Advisory |
| http://www.securityfocus.com/bid/101044 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039452 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-rbip-dos | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-12232 | US Government Resource |
Track CVE-2017-12232 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-12232), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.