← Vulnerability feed

Vulnerability record · CVE-2017-12233 · published 29 September 2017

CVE-2017-12233: Cisco IOS CIP packet parsing flaw allows remote device reload

Cisco · Ios

Cisco IOS 12.4 through 15.6 mishandles parsing of crafted Common Industrial Protocol (CIP) packets, causing an affected device to reload. Because the flaw is reachable without authentication, any network path to the CIP listener is enough to trigger a denial-of-service condition.

7.5 CVSS 3.1 High CISA KEV since 3 Mar 2022 EPSS 7.1% · top 6.0% CWE-20 · Improper input validation
7.5CVSS 3.1 base score, v2 7.8
7.1%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of crafted CIP packets destined to an affected device. An attacker could exploit these vulnerabilities by sending crafted CIP packets to be processed by an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCuz95334.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityUnauthenticated remote denial of service on network infrastructure, with confirmed exploitation per CISA KEV, though impact is limited to availability.

What it is

Cisco IOS 12.4 through 15.6 mishandles parsing of crafted Common Industrial Protocol (CIP) packets, causing an affected device to reload. Because the flaw is reachable without authentication, any network path to the CIP listener is enough to trigger a denial-of-service condition.

Impact

An attacker can force an affected device to reload, disrupting routing, switching or industrial traffic handled by that device. No confidentiality or integrity loss is described; the effect is availability only.

Attack surface

Reached remotely over the network by sending crafted CIP packets to an affected device, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required.

Exploitation

CVE-2017-12233 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating real-world exploitation; EPSS puts 30-day probability near 7.1 percent (93.9th percentile). No ransomware campaign use is documented.

What to do

  • Apply the Cisco IOS updates referenced in Cisco advisory cisco-sa-20170927-cip; this is the required action under the CISA KEV entry.
  • If CIP is not needed, disable the CIP feature on affected devices to remove the attack surface.
  • Restrict network access to CIP-enabled interfaces using ACLs or infrastructure segmentation so only trusted industrial hosts can reach them.
  • Monitor Cisco advisories for the listed Bug ID CSCuz95334 and confirm which of your IOS versions are affected before scheduling maintenance.

Detection

  • Alert on unexpected device reloads or syslog messages indicating a crash or restart on CIP-enabled IOS devices.
  • Baseline normal CIP traffic sources and flag CIP packets arriving from hosts outside the expected industrial control network.
  • Watch for repeated or malformed CIP packets targeting a single device in a short window, which may precede a reload.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-12233 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-12233 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-0171Cisco IOS Smart Install improper input validation allows remote code executionCisco IOS and IOS XE Smart Install fails to properly validate packet data, so a crafted Smart Install message sent to TCP port 4786 can overflow a bu…KEVEPSS 99%analysed9.8CVE-2017-12240Cisco IOS and IOS XE DHCP Relay Buffer Overflow RCEThe DHCP relay subsystem in Cisco IOS 12.2 through 15.6 and Cisco IOS XE contains a buffer overflow caused by improper input validation of DHCPv4 pac…KEVEPSS 14%analysed9.8CVE-2017-3881Cisco IOS/IOS XE CMP Telnet Option Handling RCECisco IOS and IOS XE fail to restrict CMP-specific Telnet options to internal cluster communications and mishandle malformed CMP Telnet options, so a…KEVEPSS 99%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.8CVE-2017-6736Cisco IOS and IOS XE SNMP buffer overflow remote code executionThe SNMP subsystem in Cisco IOS and IOS XE contains a buffer overflow that can be triggered by a crafted SNMP packet sent over IPv4 or IPv6. It affec…KEVEPSS 70%analysed8.8CVE-2017-6737Cisco IOS and IOS XE SNMP Buffer Overflow RCECisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMPv1, v2c, and v3. An authenticated remote attacker who know…KEVEPSS 45%analysed8.8CVE-2017-6738Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionThe SNMP subsystem in Cisco IOS and IOS XE Software contains a buffer overflow that affects SNMP versions 1, 2c, and 3. An authenticated remote attac…KEVEPSS 11%analysed8.8CVE-2017-6739Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionCisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMP versions 1, 2c, and 3. A remote attacker who knows the SN…KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-2017-12233), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.