Vulnerability record · CVE-2017-12235 · published 29 September 2017
CVE-2017-12235: Cisco IOS PROFINET packet parsing flaw causes device reload
Cisco · Ios
Cisco IOS releases 12.2 through 15.6 mishandle ingress PROFINET Discovery and Configuration Protocol (PN-DCP) Identify Request packets, allowing an unauthenticated remote attacker to force a device reload. Devices configured to process PROFINET messages are affected, and PROFINET is enabled by default on base switch module and expansion-unit Ethernet ports starting with IOS 12.2(52)SE. The result is a denial-of-service condition on industrial and other affected switches.
Description
A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to the improper parsing of ingress PN-DCP Identify Request packets destined to an affected device. An attacker could exploit this vulnerability by sending a crafted PN-DCP Identify Request packet to an affected device and then continuing to send normal PN-DCP Identify Request packets to the device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. This vulnerability affects Cisco devices that are configured to process PROFINET messages. Beginning with Cisco IOS Software Release 12.2(52)SE, PROFINET is enabled by default on all the base switch module and expansion-unit Ethernet ports. Cisco Bug IDs: CSCuz47179.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityThe flaw is remotely exploitable without authentication, causes full device reload, and is listed in CISA KEV as exploited in the wild, though impact is limited to availability.
What it is
Cisco IOS releases 12.2 through 15.6 mishandle ingress PROFINET Discovery and Configuration Protocol (PN-DCP) Identify Request packets, allowing an unauthenticated remote attacker to force a device reload. Devices configured to process PROFINET messages are affected, and PROFINET is enabled by default on base switch module and expansion-unit Ethernet ports starting with IOS 12.2(52)SE. The result is a denial-of-service condition on industrial and other affected switches.
Impact
An attacker can cause the targeted device to reload repeatedly, disrupting network availability and any industrial or operational traffic carried through it. No confidentiality or integrity impact is described; the effect is availability loss only.
Attack surface
The flaw is reached over the network by sending crafted PN-DCP Identify Request packets to a device that processes PROFINET messages, followed by normal PN-DCP Identify Request packets. The CVSS vector shows no privileges and no user interaction required, so it is remotely triggerable by an unauthenticated attacker with network reach to the affected interface.
Exploitation
CVE-2017-12235 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating real-world exploitation, and EPSS shows a 30-day probability of about 7.1 percent (93.9th percentile). References are vendor advisory and government catalog entries; no public exploit code is cited in the record.
What to do
- Apply the Cisco IOS updates specified in the vendor advisory cisco-sa-20170927-profinet; this is the primary fix.
- Where PROFINET is not required, disable PROFINET processing on affected switch and expansion-unit Ethernet ports.
- Restrict network access to PROFINET-capable interfaces using ACLs or segmentation so only trusted industrial hosts can send PN-DCP traffic.
- Monitor for repeated device reloads on PROFINET-enabled switches and treat unexplained reloads as potential exploitation.
- Track remediation against the CISA KEV due date and confirm affected devices are upgraded or isolated.
Detection
- Alert on unexpected or repeated reload/restart events on Cisco IOS devices that process PROFINET.
- Inspect network traffic for PN-DCP Identify Request packets arriving from untrusted or unexpected sources.
- Baseline which hosts legitimately send PROFINET discovery traffic and flag deviations.
- Correlate device reload logs with PN-DCP packet captures to identify crafted-packet triggers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-12235 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/101043 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039451 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-profinet | Vendor Advisory |
| http://www.securityfocus.com/bid/101043 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039451 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-profinet | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-12235 | US Government Resource |
Track CVE-2017-12235 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-12235), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.