← All CVEs

CVE-2017-12238

medium · 6.5Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-03-03Remediation due 2022-03-24

A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a denial of service (DoS) condition. The vulnerability is due to a memory management issue in the affected software. An attacker could exploit this vulnerability by creating a large number of VPLS-generated MAC entries in the MAC address table of an affected device. A successful exploit could allow the attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a DoS condition. This vulnerability affects Cisco Catalyst 6800 Series Switches that are running a vulnerable release of Cisco IOS Software and have a Cisco C6800-16P10G or C6800-16P10G-XL line card in use with Supervisor Engine 6T. To be vulnerable, the device must also be configured with VPLS and the C6800-16P10G or C6800-16P10G-XL line card needs to be the core-facing MPLS interfaces. Cisco Bug IDs: CSCva61927.

6.5
CVSS
2.0%
EPSS (exploit prob.)
80th
EPSS percentile
2017-09-29
Published

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-399

Affected products

VendorProductAffected versions
ciscoios>= 15.0, <= 15.4
ciscoc6800-16p10gall versions
ciscoc6800-16p10g-xlall versions
ciscocatalyst_6000all versions
ciscocatalyst_6000_ws-svc-nam-12.2(1a)
ciscocatalyst_6000_ws-svc-nam-13.1(1a)
ciscocatalyst_6000_ws-svc-nam-22.2(1a)
ciscocatalyst_6000_ws-svc-nam-23.1(1a)
ciscocatalyst_6000_ws-x6380-nam2.1(2)
ciscocatalyst_6000_ws-x6380-nam3.1(1a)
ciscocatalyst_6500all versions
ciscocatalyst_6500-eall versions
ciscocatalyst_6500_ws-svc-nam-12.2(1a)
ciscocatalyst_6500_ws-svc-nam-13.1(1a)
ciscocatalyst_6500_ws-svc-nam-22.2(1a)
ciscocatalyst_6500_ws-svc-nam-23.1(1a)
ciscocatalyst_6500_ws-x6380-nam2.1(2)
ciscocatalyst_6500_ws-x6380-nam3.1(1a)
ciscocatalyst_6503-eall versions
ciscocatalyst_6504-eall versions
ciscocatalyst_6506-eall versions
ciscocatalyst_6509-eall versions
ciscocatalyst_6509-neb-aall versions
ciscocatalyst_6509-v-eall versions
ciscocatalyst_6513all versions
ciscocatalyst_6513-eall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-12238