← All CVEs

CVE-2017-12235

high · 7.5Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-03-03Remediation due 2022-03-24

A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to the improper parsing of ingress PN-DCP Identify Request packets destined to an affected device. An attacker could exploit this vulnerability by sending a crafted PN-DCP Identify Request packet to an affected device and then continuing to send normal PN-DCP Identify Request packets to the device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. This vulnerability affects Cisco devices that are configured to process PROFINET messages. Beginning with Cisco IOS Software Release 12.2(52)SE, PROFINET is enabled by default on all the base switch module and expansion-unit Ethernet ports. Cisco Bug IDs: CSCuz47179.

7.5
CVSS
7.1%
EPSS (exploit prob.)
94th
EPSS percentile
2017-09-29
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
ciscoios>= 12.2, <= 15.6
ciscoindustrial_ethernet_2000_16ptc-g-e_switchall versions
ciscoindustrial_ethernet_2000_16ptc-g-l_switchall versions
ciscoindustrial_ethernet_2000_16ptc-g-nx_switchall versions
ciscoindustrial_ethernet_2000_16t67-b_switchall versions
ciscoindustrial_ethernet_2000_16t67p-g-e_switchall versions
ciscoindustrial_ethernet_2000_16tc-g-e_switchall versions
ciscoindustrial_ethernet_2000_16tc-g-l_switchall versions
ciscoindustrial_ethernet_2000_16tc-g-n_switchall versions
ciscoindustrial_ethernet_2000_16tc-g-x_switchall versions
ciscoindustrial_ethernet_2000_16tc-l_switchall versions
ciscoindustrial_ethernet_2000_24t67-b_switchall versions
ciscoindustrial_ethernet_2000_4s-ts-g-b_switchall versions
ciscoindustrial_ethernet_2000_4s-ts-g-l_switchall versions
ciscoindustrial_ethernet_2000_4t-b_switchall versions
ciscoindustrial_ethernet_2000_4t-g-b_switchall versions
ciscoindustrial_ethernet_2000_4t-g-l_switchall versions
ciscoindustrial_ethernet_2000_4t-l_switchall versions
ciscoindustrial_ethernet_2000_4ts-b_switchall versions
ciscoindustrial_ethernet_2000_4ts-g-b_switchall versions
ciscoindustrial_ethernet_2000_4ts-g-l_switchall versions
ciscoindustrial_ethernet_2000_4ts-l_switchall versions
ciscoindustrial_ethernet_2000_8t67-b_switchall versions
ciscoindustrial_ethernet_2000_8t67p-g-e_switchall versions
ciscoindustrial_ethernet_2000_8tc-b_switchall versions
ciscoindustrial_ethernet_2000_8tc-g-b_switchall versions
ciscoindustrial_ethernet_2000_8tc-g-e_switchall versions
ciscoindustrial_ethernet_2000_8tc-g-l_switchall versions
ciscoindustrial_ethernet_2000_8tc-g-n_switchall versions
ciscoindustrial_ethernet_2000_8tc-l_switchall versions
ciscoindustrial_ethernet_2000_series_firmware15.2(5.4.32i)e2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-12235