Vulnerability record · CVE-2017-12319 · published 27 March 2018
CVE-2017-12319: Cisco IOS XE BGP EVPN packet parsing flaw causes device reload
Cisco · Ios
Cisco IOS XE Software mishandles the IP address length field when processing BGP EVPN Inclusive Multicast Ethernet Tag or MAC/IP Advertisement Route updates, due to implementation changes against the RFC 7432 draft. A crafted BGP update sent over an established session can reload the device or corrupt the BGP routing table, disrupting network routing. Only devices configured for BGP EVPN are affected.
Description
A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability. The vulnerability exists due to changes in the implementation of the BGP MPLS-Based Ethernet VPN RFC (RFC 7432) draft between IOS XE software releases. When the BGP Inclusive Multicast Ethernet Tag Route or BGP EVPN MAC/IP Advertisement Route update packet is received, it could be possible that the IP address length field is miscalculated. An attacker could exploit this vulnerability by sending a crafted BGP packet to an affected device after the BGP session was established. An exploit could allow the attacker to cause the affected device to reload or corrupt the BGP routing table; either outcome would result in a DoS. The vulnerability may be triggered when the router receives a crafted BGP message from a peer on an existing BGP session. This vulnerability affects all releases of Cisco IOS XE Software prior to software release 16.3 that support BGP EVPN configurations. If the device is not configured for EVPN, it is not vulnerable. Cisco Bug IDs: CSCui67191, CSCvg52875.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityThe flaw is remotely triggerable without authentication and is listed in CISA KEV as exploited, though it requires an established BGP session and EVPN configuration and yields only denial of service.
What it is
Cisco IOS XE Software mishandles the IP address length field when processing BGP EVPN Inclusive Multicast Ethernet Tag or MAC/IP Advertisement Route updates, due to implementation changes against the RFC 7432 draft. A crafted BGP update sent over an established session can reload the device or corrupt the BGP routing table, disrupting network routing. Only devices configured for BGP EVPN are affected.
Impact
An unauthenticated remote peer can force the device to reload or corrupt its BGP routing table, producing a denial-of-service condition and possible network instability. No confidentiality or integrity of data beyond routing state is described.
Attack surface
Reached over the network via BGP; the attacker must send a crafted BGP update after a BGP session is established, so a peer relationship is required but no user interaction is needed. Devices not configured for EVPN are not vulnerable.
Exploitation
CVE-2017-12319 is listed in CISA KEV with a 2022-03-03 addition and a 2022-03-24 remediation due date, indicating known exploitation; EPSS 30-day probability is about 5.2 percent (92nd percentile). No ransomware campaign use is recorded.
What to do
- Upgrade Cisco IOS XE Software to release 16.3 or later, which contains the fix per the vendor advisory.
- If immediate upgrade is not possible, remove or disable BGP EVPN configurations on affected devices where the feature is not required.
- Restrict BGP peering to trusted, authenticated peers and apply prefix and route-update filtering on EVPN sessions.
- Monitor Cisco advisory cisco-sa-20171103-bgp and CISA KEV guidance for updated remediation instructions.
Detection
- Alert on unexpected device reloads or BGP process restarts on IOS XE routers running EVPN.
- Monitor BGP EVPN update logs for malformed or anomalous IP address length fields in Inclusive Multicast Ethernet Tag and MAC/IP Advertisement Route messages.
- Track BGP session resets and routing table churn from EVPN peers for signs of corruption or instability.
- Review BGP peer inventories to confirm which devices have EVPN enabled and are therefore exposed.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-12319 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/101676 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171103-bgp | Vendor Advisory |
| http://www.securityfocus.com/bid/101676 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171103-bgp | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-12319 | US Government Resource |
Track CVE-2017-12319 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-12319), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.