← Vulnerability feed

Vulnerability record · CVE-2017-12238 · published 29 September 2017

CVE-2017-12238: Cisco IOS VPLS memory management flaw crashes Catalyst 6800 line cards

Cisco · Ios

Cisco IOS 15.0 through 15.4 on Catalyst 6800 Series Switches has a memory management issue in the VPLS code. An adjacent, unauthenticated attacker can flood VPLS-generated MAC entries into the MAC address table and crash a C6800-16P10G or C6800-16P10G-XL line card, causing a denial of service.

6.5 CVSS 3.1 Medium CISA KEV since 3 Mar 2022 EPSS 2.0% · top 19.9% CWE-399 · CWE-399
6.5CVSS 3.1 base score, v2 3.3
2.0%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a denial of service (DoS) condition. The vulnerability is due to a memory management issue in the affected software. An attacker could exploit this vulnerability by creating a large number of VPLS-generated MAC entries in the MAC address table of an affected device. A successful exploit could allow the attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a DoS condition. This vulnerability affects Cisco Catalyst 6800 Series Switches that are running a vulnerable release of Cisco IOS Software and have a Cisco C6800-16P10G or C6800-16P10G-XL line card in use with Supervisor Engine 6T. To be vulnerable, the device must also be configured with VPLS and the C6800-16P10G or C6800-16P10G-XL line card needs to be the core-facing MPLS interfaces. Cisco Bug IDs: CSCva61927.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw is remotely triggerable by an adjacent unauthenticated attacker and is listed in CISA KEV as exploited, though it only causes denial of service on a specific hardware and configuration combination.

What it is

Cisco IOS 15.0 through 15.4 on Catalyst 6800 Series Switches has a memory management issue in the VPLS code. An adjacent, unauthenticated attacker can flood VPLS-generated MAC entries into the MAC address table and crash a C6800-16P10G or C6800-16P10G-XL line card, causing a denial of service.

Impact

The attacker can crash the affected line card, taking the device out of service and disrupting traffic through it. No confidentiality or integrity impact is described; the effect is availability loss.

Attack surface

Reachable by an adjacent attacker on the network, with no authentication and no user interaction required (CVSS vector AV:A/PR:N/UI:N). The device must run a vulnerable IOS release, use a C6800-16P10G or C6800-16P10G-XL line card with Supervisor Engine 6T, be configured with VPLS, and have that line card as the core-facing MPLS interface.

Exploitation

CVE-2017-12238 is listed in CISA's Known Exploited Vulnerabilities catalog with a 2022-03-03 addition date, indicating known exploitation. EPSS is low at roughly 2.0% 30-day probability (80th percentile), and no ransomware campaign use is documented.

What to do

  • Apply the Cisco IOS software update referenced in Cisco advisory cisco-sa-20170927-vpls for affected Catalyst 6800 switches.
  • Verify whether the device meets all vulnerable preconditions: IOS 15.0-15.4, C6800-16P10G or C6800-16P10G-XL line card with Supervisor Engine 6T, VPLS configured, and the line card used as the core-facing MPLS interface.
  • If patching cannot be done immediately, restrict adjacency to the affected VPLS/MPLS interfaces to trusted network segments.
  • Monitor MAC address table growth on affected line cards and treat abnormal VPLS MAC entry counts as an indicator of attack.
  • Track CISA KEV remediation due dates for this CVE and confirm closure.

Detection

  • Alert on abnormal growth in VPLS-generated MAC entries in the MAC address table of Catalyst 6800 switches.
  • Monitor for line card crash, reload, or reset events on C6800-16P10G and C6800-16P10G-XL cards.
  • Watch syslog and SNMP traps for VPLS or MAC table related errors preceding a line card failure.
  • Baseline normal VPLS MAC entry counts per interface and flag deviations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-12238 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-12238 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-0171Cisco IOS Smart Install improper input validation allows remote code executionCisco IOS and IOS XE Smart Install fails to properly validate packet data, so a crafted Smart Install message sent to TCP port 4786 can overflow a bu…KEVEPSS 99%analysed9.8CVE-2017-12240Cisco IOS and IOS XE DHCP Relay Buffer Overflow RCEThe DHCP relay subsystem in Cisco IOS 12.2 through 15.6 and Cisco IOS XE contains a buffer overflow caused by improper input validation of DHCPv4 pac…KEVEPSS 14%analysed9.8CVE-2017-3881Cisco IOS/IOS XE CMP Telnet Option Handling RCECisco IOS and IOS XE fail to restrict CMP-specific Telnet options to internal cluster communications and mishandle malformed CMP Telnet options, so a…KEVEPSS 99%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.8CVE-2017-6736Cisco IOS and IOS XE SNMP buffer overflow remote code executionThe SNMP subsystem in Cisco IOS and IOS XE contains a buffer overflow that can be triggered by a crafted SNMP packet sent over IPv4 or IPv6. It affec…KEVEPSS 70%analysed8.8CVE-2017-6737Cisco IOS and IOS XE SNMP Buffer Overflow RCECisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMPv1, v2c, and v3. An authenticated remote attacker who know…KEVEPSS 45%analysed8.8CVE-2017-6738Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionThe SNMP subsystem in Cisco IOS and IOS XE Software contains a buffer overflow that affects SNMP versions 1, 2c, and 3. An authenticated remote attac…KEVEPSS 11%analysed8.8CVE-2017-6739Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionCisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMP versions 1, 2c, and 3. A remote attacker who knows the SN…KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-2017-12238), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.