← Vulnerability feed

Vulnerability record · CVE-2017-12319 · published 27 March 2018

CVE-2017-12319: Cisco IOS XE BGP EVPN packet parsing flaw causes device reload

Cisco · Ios

Cisco IOS XE Software mishandles the IP address length field when processing BGP EVPN Inclusive Multicast Ethernet Tag or MAC/IP Advertisement Route updates, due to implementation changes against the RFC 7432 draft. A crafted BGP update sent over an established session can reload the device or corrupt the BGP routing table, disrupting network routing. Only devices configured for BGP EVPN are affected.

5.9 CVSS 3.1 Medium CISA KEV since 3 Mar 2022 EPSS 5.2% · top 7.8% CWE-20 · Improper input validation
5.9CVSS 3.1 base score, v2 7.1
5.2%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability. The vulnerability exists due to changes in the implementation of the BGP MPLS-Based Ethernet VPN RFC (RFC 7432) draft between IOS XE software releases. When the BGP Inclusive Multicast Ethernet Tag Route or BGP EVPN MAC/IP Advertisement Route update packet is received, it could be possible that the IP address length field is miscalculated. An attacker could exploit this vulnerability by sending a crafted BGP packet to an affected device after the BGP session was established. An exploit could allow the attacker to cause the affected device to reload or corrupt the BGP routing table; either outcome would result in a DoS. The vulnerability may be triggered when the router receives a crafted BGP message from a peer on an existing BGP session. This vulnerability affects all releases of Cisco IOS XE Software prior to software release 16.3 that support BGP EVPN configurations. If the device is not configured for EVPN, it is not vulnerable. Cisco Bug IDs: CSCui67191, CSCvg52875.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw is remotely triggerable without authentication and is listed in CISA KEV as exploited, though it requires an established BGP session and EVPN configuration and yields only denial of service.

What it is

Cisco IOS XE Software mishandles the IP address length field when processing BGP EVPN Inclusive Multicast Ethernet Tag or MAC/IP Advertisement Route updates, due to implementation changes against the RFC 7432 draft. A crafted BGP update sent over an established session can reload the device or corrupt the BGP routing table, disrupting network routing. Only devices configured for BGP EVPN are affected.

Impact

An unauthenticated remote peer can force the device to reload or corrupt its BGP routing table, producing a denial-of-service condition and possible network instability. No confidentiality or integrity of data beyond routing state is described.

Attack surface

Reached over the network via BGP; the attacker must send a crafted BGP update after a BGP session is established, so a peer relationship is required but no user interaction is needed. Devices not configured for EVPN are not vulnerable.

Exploitation

CVE-2017-12319 is listed in CISA KEV with a 2022-03-03 addition and a 2022-03-24 remediation due date, indicating known exploitation; EPSS 30-day probability is about 5.2 percent (92nd percentile). No ransomware campaign use is recorded.

What to do

  • Upgrade Cisco IOS XE Software to release 16.3 or later, which contains the fix per the vendor advisory.
  • If immediate upgrade is not possible, remove or disable BGP EVPN configurations on affected devices where the feature is not required.
  • Restrict BGP peering to trusted, authenticated peers and apply prefix and route-update filtering on EVPN sessions.
  • Monitor Cisco advisory cisco-sa-20171103-bgp and CISA KEV guidance for updated remediation instructions.

Detection

  • Alert on unexpected device reloads or BGP process restarts on IOS XE routers running EVPN.
  • Monitor BGP EVPN update logs for malformed or anomalous IP address length fields in Inclusive Multicast Ethernet Tag and MAC/IP Advertisement Route messages.
  • Track BGP session resets and routing table churn from EVPN peers for signs of corruption or instability.
  • Review BGP peer inventories to confirm which devices have EVPN enabled and are therefore exposed.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-12319 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-12319 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2023-20198Cisco IOS XE Web UI unauthenticated privilege escalation and implant deploymentCVE-2023-20198 is a critical flaw in the Cisco IOS XE web UI that lets an unauthenticated remote attacker gain initial access and create a local priv…KEVEPSS 100%analysed9.8CVE-2018-0171Cisco IOS Smart Install improper input validation allows remote code executionCisco IOS and IOS XE Smart Install fails to properly validate packet data, so a crafted Smart Install message sent to TCP port 4786 can overflow a bu…KEVEPSS 99%analysed9.8CVE-2018-0151Cisco IOS/IOS XE QoS UDP Port 18999 Buffer OverflowCisco IOS and IOS XE contain a buffer overflow in the QoS subsystem caused by incorrect bounds checking of values in packets sent to UDP port 18999. …KEVEPSS 14%analysed9.8CVE-2017-12240Cisco IOS and IOS XE DHCP Relay Buffer Overflow RCEThe DHCP relay subsystem in Cisco IOS 12.2 through 15.6 and Cisco IOS XE contains a buffer overflow caused by improper input validation of DHCPv4 pac…KEVEPSS 14%analysed9.8CVE-2017-3881Cisco IOS/IOS XE CMP Telnet Option Handling RCECisco IOS and IOS XE fail to restrict CMP-specific Telnet options to internal cluster communications and mishandle malformed CMP Telnet options, so a…KEVEPSS 99%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.8CVE-2017-6736Cisco IOS and IOS XE SNMP buffer overflow remote code executionThe SNMP subsystem in Cisco IOS and IOS XE contains a buffer overflow that can be triggered by a crafted SNMP packet sent over IPv4 or IPv6. It affec…KEVEPSS 70%analysed8.8CVE-2017-6737Cisco IOS and IOS XE SNMP Buffer Overflow RCECisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMPv1, v2c, and v3. An authenticated remote attacker who know…KEVEPSS 45%analysed

Source: NIST National Vulnerability Database (record CVE-2017-12319), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.