Vulnerability record · CVE-2017-12234 · published 29 September 2017
CVE-2017-12234: Cisco IOS CIP packet parsing flaw allows remote device reload
Cisco · Ios
Cisco IOS 12.4 through 15.6 improperly parses crafted Common Industrial Protocol (CIP) packets, allowing an unauthenticated remote attacker to reload the device. The result is a denial-of-service condition on affected routers and switches running the CIP feature. The record does not list specific affected hardware platforms or the exact fixed releases beyond the version range.
Description
Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of crafted CIP packets destined to an affected device. An attacker could exploit these vulnerabilities by sending crafted CIP packets to be processed by an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvc43709.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityUnauthenticated remote availability impact (CVSS 7.5) combined with confirmed exploitation in CISA KEV raises urgency despite the DoS-only impact.
What it is
Cisco IOS 12.4 through 15.6 improperly parses crafted Common Industrial Protocol (CIP) packets, allowing an unauthenticated remote attacker to reload the device. The result is a denial-of-service condition on affected routers and switches running the CIP feature. The record does not list specific affected hardware platforms or the exact fixed releases beyond the version range.
Impact
An attacker can force an affected device to reload, causing a denial of service. There is no confidentiality or integrity impact; only availability is affected.
Attack surface
Reachable over the network by sending crafted CIP packets to the affected device, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required.
Exploitation
CVE-2017-12234 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating exploitation in the wild; EPSS 30-day probability is 0.07128 (93.9th percentile). No ransomware campaign use is documented.
What to do
- Apply the Cisco IOS updates referenced in Cisco advisory cisco-sa-20170927-cip; this is the primary fix.
- If CIP is not required, disable the CIP feature on affected devices to remove the attack surface.
- Restrict network access to CIP-exposed interfaces using ACLs and infrastructure segmentation so only trusted hosts can reach them.
- Monitor Cisco advisories for updated fixed-release guidance and verify device software versions against the advisory.
Detection
- Alert on unexpected device reloads or syslog messages indicating reload/crash on CIP-enabled Cisco IOS devices.
- Monitor for anomalous or malformed CIP traffic directed at affected devices, especially from untrusted network segments.
- Baseline normal CIP peer traffic and flag new or unexpected source addresses sending CIP packets.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-12234 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/101038 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039459 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-cip | Vendor Advisory |
| http://www.securityfocus.com/bid/101038 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039459 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-cip | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-12234 | US Government Resource |
Track CVE-2017-12234 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-12234), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.