Vulnerability record · CVE-2017-12237 · published 29 September 2017
CVE-2017-12237: Cisco IOS and IOS XE IKEv2 packet handling denial of service
Cisco · Ios
Cisco IOS 15.0 through 15.6 and IOS XE 3.5 through 16.5 mishandle certain IKEv2 packets, causing high CPU utilization, traceback messages, or a device reload. Any device with ISAKMP enabled is exposed, even without IKEv2-specific configuration, so the affected footprint is broad.
Description
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to how an affected device processes certain IKEv2 packets. An attacker could exploit this vulnerability by sending specific IKEv2 packets to an affected device to be processed. A successful exploit could allow the attacker to cause high CPU utilization, traceback messages, or a reload of the affected device that leads to a DoS condition. This vulnerability affects Cisco devices that have the Internet Security Association and Key Management Protocol (ISAKMP) enabled. Although only IKEv2 packets can be used to trigger this vulnerability, devices that are running Cisco IOS Software or Cisco IOS XE Software are vulnerable when ISAKMP is enabled. A device does not need to be configured with any IKEv2-specific features to be vulnerable. Many features use IKEv2, including different types of VPNs such as the following: LAN-to-LAN VPN; Remote-access VPN, excluding SSL VPN; Dynamic Multipoint VPN (DMVPN); and FlexVPN. Cisco Bug IDs: CSCvc41277.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityUnauthenticated remote denial of service with a 7.5 CVSS score and confirmed KEV listing, though impact is availability-only.
What it is
Cisco IOS 15.0 through 15.6 and IOS XE 3.5 through 16.5 mishandle certain IKEv2 packets, causing high CPU utilization, traceback messages, or a device reload. Any device with ISAKMP enabled is exposed, even without IKEv2-specific configuration, so the affected footprint is broad.
Impact
An unauthenticated remote attacker can drive CPU exhaustion or force a reload, producing a denial-of-service condition on the affected device.
Attack surface
Reachable over the network via IKEv2 packets sent to a device with ISAKMP enabled; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
CVE-2017-12237 is listed in CISA KEV with a 2022-03-03 addition date, indicating known exploitation; EPSS 30-day probability is about 7.1 percent (93.9th percentile). No ransomware campaign use is documented.
What to do
- Apply the Cisco IOS/IOS XE updates referenced in Cisco advisory cisco-sa-20170927-ike.
- Where IKEv2 is not required, disable ISAKMP/IKEv2 on internet-facing interfaces.
- Restrict IKEv2 (UDP 500/4500) reachability to trusted peer addresses with ACLs or infrastructure ACLs.
- Monitor and rate-limit IKEv2 traffic to affected devices to blunt packet floods.
- Track CISA KEV remediation due dates for any remaining unpatched devices.
Detection
- Alert on IKEv2 (UDP 500/4500) traffic spikes or unusual packet patterns toward Cisco IOS/IOS XE devices.
- Monitor device logs for traceback messages, unexpected reloads, and CPU threshold alarms.
- Baseline normal IKEv2 peer addresses and flag IKEv2 packets from unexpected sources.
- Correlate device reload or high-CPU events with concurrent IKEv2 traffic volume.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-12237 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/101037 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039460 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-ike | Vendor Advisory |
| http://www.securityfocus.com/bid/101037 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1039460 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-ike | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-12237 | US Government Resource |
Track CVE-2017-12237 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-12237), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.