← Vulnerability feed

Vulnerability record · CVE-2017-12240 · published 29 September 2017

CVE-2017-12240: Cisco IOS and IOS XE DHCP Relay Buffer Overflow RCE

Cisco · Ios

The DHCP relay subsystem in Cisco IOS 12.2 through 15.6 and Cisco IOS XE contains a buffer overflow caused by improper input validation of DHCPv4 packets. An unauthenticated remote attacker can send a crafted DHCPv4 packet to trigger the overflow, potentially executing arbitrary code or reloading the device.

9.8 CVSS 3.1 Critical CISA KEV since 3 Mar 2022 EPSS 14% · top 3.6% CWE-20 · Improper input validationCWE-119 · Memory buffer overflow
9.8CVSS 3.1 base score, v2 10.0
14%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
11References
17 Jun 2026Last modified by NVD

Description

The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system. The attacker could also cause an affected system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to a buffer overflow condition in the DHCP relay subsystem of the affected software. An attacker could exploit this vulnerability by sending a crafted DHCP Version 4 (DHCPv4) packet to an affected system. A successful exploit could allow the attacker to execute arbitrary code and gain full control of the affected system or cause the affected system to reload, resulting in a DoS condition. Cisco Bug IDs: CSCsm45390, CSCuw77959.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network-reachable, unauthenticated remote code execution and confirmed inclusion in CISA's KEV catalog.

What it is

The DHCP relay subsystem in Cisco IOS 12.2 through 15.6 and Cisco IOS XE contains a buffer overflow caused by improper input validation of DHCPv4 packets. An unauthenticated remote attacker can send a crafted DHCPv4 packet to trigger the overflow, potentially executing arbitrary code or reloading the device.

Impact

Successful exploitation gives the attacker arbitrary code execution and full control of the affected device, or causes a reload resulting in denial of service.

Attack surface

Reachable over the network via a crafted DHCPv4 packet sent to the DHCP relay subsystem; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

CVE-2017-12240 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating known exploitation in the wild; EPSS 30-day probability is 0.13883 (96.3rd percentile).

What to do

  • Apply the Cisco updates referenced in the vendor advisory cisco-sa-20170927-dhcp (Bug IDs CSCsm45390, CSCuw77959).
  • If patching cannot be done immediately, disable or restrict the DHCP relay service on affected interfaces where it is not required.
  • Filter or rate-limit inbound DHCPv4 traffic to the device's relay-facing interfaces using infrastructure ACLs.
  • Segment management and relay traffic so untrusted networks cannot reach the DHCP relay subsystem directly.
  • Track CISA KEV remediation due date (2022-03-24) and confirm closure of the finding.

Detection

  • Monitor device logs for unexpected reloads, crashes, or DHCP relay process restarts.
  • Alert on malformed or oversized DHCPv4 packets directed at the device's relay interfaces.
  • Baseline and review DHCP relay configuration changes and interface exposure on IOS/IOS XE devices.
  • Correlate CISA KEV status and asset inventory to identify unpatched IOS/IOS XE devices still running DHCP relay.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-12240 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-12240 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-0171Cisco IOS Smart Install improper input validation allows remote code executionCisco IOS and IOS XE Smart Install fails to properly validate packet data, so a crafted Smart Install message sent to TCP port 4786 can overflow a bu…KEVEPSS 99%analysed9.8CVE-2017-3881Cisco IOS/IOS XE CMP Telnet Option Handling RCECisco IOS and IOS XE fail to restrict CMP-specific Telnet options to internal cluster communications and mishandle malformed CMP Telnet options, so a…KEVEPSS 99%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.8CVE-2017-6736Cisco IOS and IOS XE SNMP buffer overflow remote code executionThe SNMP subsystem in Cisco IOS and IOS XE contains a buffer overflow that can be triggered by a crafted SNMP packet sent over IPv4 or IPv6. It affec…KEVEPSS 70%analysed8.8CVE-2017-6737Cisco IOS and IOS XE SNMP Buffer Overflow RCECisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMPv1, v2c, and v3. An authenticated remote attacker who know…KEVEPSS 45%analysed8.8CVE-2017-6738Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionThe SNMP subsystem in Cisco IOS and IOS XE Software contains a buffer overflow that affects SNMP versions 1, 2c, and 3. An authenticated remote attac…KEVEPSS 11%analysed8.8CVE-2017-6739Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionCisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMP versions 1, 2c, and 3. A remote attacker who knows the SN…KEVEPSS 11%analysed8.8CVE-2017-6740Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionCisco IOS and IOS XE contain a buffer overflow in the SNMP subsystem affecting SNMP versions 1, 2c, and 3. An authenticated remote attacker can send …KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-2017-12240), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.