← Vulnerability feed

Vulnerability record · CVE-2017-12237 · published 29 September 2017

CVE-2017-12237: Cisco IOS and IOS XE IKEv2 packet handling denial of service

Cisco · Ios

Cisco IOS 15.0 through 15.6 and IOS XE 3.5 through 16.5 mishandle certain IKEv2 packets, causing high CPU utilization, traceback messages, or a device reload. Any device with ISAKMP enabled is exposed, even without IKEv2-specific configuration, so the affected footprint is broad.

7.5 CVSS 3.1 High CISA KEV since 3 Mar 2022 EPSS 7.1% · top 6.0% CWE-399 · CWE-399
7.5CVSS 3.1 base score, v2 7.8
7.1%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to how an affected device processes certain IKEv2 packets. An attacker could exploit this vulnerability by sending specific IKEv2 packets to an affected device to be processed. A successful exploit could allow the attacker to cause high CPU utilization, traceback messages, or a reload of the affected device that leads to a DoS condition. This vulnerability affects Cisco devices that have the Internet Security Association and Key Management Protocol (ISAKMP) enabled. Although only IKEv2 packets can be used to trigger this vulnerability, devices that are running Cisco IOS Software or Cisco IOS XE Software are vulnerable when ISAKMP is enabled. A device does not need to be configured with any IKEv2-specific features to be vulnerable. Many features use IKEv2, including different types of VPNs such as the following: LAN-to-LAN VPN; Remote-access VPN, excluding SSL VPN; Dynamic Multipoint VPN (DMVPN); and FlexVPN. Cisco Bug IDs: CSCvc41277.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityUnauthenticated remote denial of service with a 7.5 CVSS score and confirmed KEV listing, though impact is availability-only.

What it is

Cisco IOS 15.0 through 15.6 and IOS XE 3.5 through 16.5 mishandle certain IKEv2 packets, causing high CPU utilization, traceback messages, or a device reload. Any device with ISAKMP enabled is exposed, even without IKEv2-specific configuration, so the affected footprint is broad.

Impact

An unauthenticated remote attacker can drive CPU exhaustion or force a reload, producing a denial-of-service condition on the affected device.

Attack surface

Reachable over the network via IKEv2 packets sent to a device with ISAKMP enabled; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

CVE-2017-12237 is listed in CISA KEV with a 2022-03-03 addition date, indicating known exploitation; EPSS 30-day probability is about 7.1 percent (93.9th percentile). No ransomware campaign use is documented.

What to do

  • Apply the Cisco IOS/IOS XE updates referenced in Cisco advisory cisco-sa-20170927-ike.
  • Where IKEv2 is not required, disable ISAKMP/IKEv2 on internet-facing interfaces.
  • Restrict IKEv2 (UDP 500/4500) reachability to trusted peer addresses with ACLs or infrastructure ACLs.
  • Monitor and rate-limit IKEv2 traffic to affected devices to blunt packet floods.
  • Track CISA KEV remediation due dates for any remaining unpatched devices.

Detection

  • Alert on IKEv2 (UDP 500/4500) traffic spikes or unusual packet patterns toward Cisco IOS/IOS XE devices.
  • Monitor device logs for traceback messages, unexpected reloads, and CPU threshold alarms.
  • Baseline normal IKEv2 peer addresses and flag IKEv2 packets from unexpected sources.
  • Correlate device reload or high-CPU events with concurrent IKEv2 traffic volume.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-12237 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-12237 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2023-20198Cisco IOS XE Web UI unauthenticated privilege escalation and implant deploymentCVE-2023-20198 is a critical flaw in the Cisco IOS XE web UI that lets an unauthenticated remote attacker gain initial access and create a local priv…KEVEPSS 100%analysed9.8CVE-2018-0171Cisco IOS Smart Install improper input validation allows remote code executionCisco IOS and IOS XE Smart Install fails to properly validate packet data, so a crafted Smart Install message sent to TCP port 4786 can overflow a bu…KEVEPSS 99%analysed9.8CVE-2018-0151Cisco IOS/IOS XE QoS UDP Port 18999 Buffer OverflowCisco IOS and IOS XE contain a buffer overflow in the QoS subsystem caused by incorrect bounds checking of values in packets sent to UDP port 18999. …KEVEPSS 14%analysed9.8CVE-2017-12240Cisco IOS and IOS XE DHCP Relay Buffer Overflow RCEThe DHCP relay subsystem in Cisco IOS 12.2 through 15.6 and Cisco IOS XE contains a buffer overflow caused by improper input validation of DHCPv4 pac…KEVEPSS 14%analysed9.8CVE-2017-3881Cisco IOS/IOS XE CMP Telnet Option Handling RCECisco IOS and IOS XE fail to restrict CMP-specific Telnet options to internal cluster communications and mishandle malformed CMP Telnet options, so a…KEVEPSS 99%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.8CVE-2017-6736Cisco IOS and IOS XE SNMP buffer overflow remote code executionThe SNMP subsystem in Cisco IOS and IOS XE contains a buffer overflow that can be triggered by a crafted SNMP packet sent over IPv4 or IPv6. It affec…KEVEPSS 70%analysed8.8CVE-2017-6737Cisco IOS and IOS XE SNMP Buffer Overflow RCECisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMPv1, v2c, and v3. An authenticated remote attacker who know…KEVEPSS 45%analysed

Source: NIST National Vulnerability Database (record CVE-2017-12237), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.