Cyber Resilience

CVE-2017-12232

Cisco Ios 15.0 – 15.6

CISA KEVActive ExploitationEUVD Exploited
Published
29 September 2017
Modified
22 April 2026
KEV Added
03 March 2022
Patch / advisory
CVSS Score v3.1 6.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score 0.022 81th percentile
Risk Priority 76 floored blend · peak EPSS

Summary

CVE-2017-12232 is a medium-severity an unspecified weakness vulnerability in Cisco Ios. Its CVSS base score is 6.5 (Medium).

Operationally, ranked in the top 19% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

A vulnerability in the protocol implementation on Cisco Integrated Services Routers Generation 2 (ISR G2) running IOS versions 15.0 through 15.6 permits an unauthenticated adjacent attacker to trigger a device reload. The root cause is misclassification of Ethernet frames, tracked under Cisco Bug ID CSCvc03809 and assigned CWE-399. The flaw affects only the listed router platforms and IOS releases; successful exploitation produces a denial-of-service condition without requiring authentication or user interaction.

An attacker positioned on the same Layer-2 network can send a single crafted Ethernet frame to an affected interface. Because the device incorrectly classifies the frame, it enters an error-handling path that forces a reload. The CVSS vector (AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) reflects the requirement for adjacency and the high impact on availability.

The Cisco Security Advisory cisco-sa-20170927-rbip-dos, along with the associated SecurityFocus and SecurityTracker entries, directs administrators to the fixed software releases and any available workarounds for the listed IOS versions. No reports of in-the-wild exploitation appear in the provided references.

EU & UK References

Vulnerability Data

A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through 15.6 could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a…

more

denial of service (DoS) condition. The vulnerability is due to a misclassification of Ethernet frames. An attacker could exploit this vulnerability by sending a crafted Ethernet frame to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvc03809.

CWE(s)
KEV Date Added
03 March 2022

Related Threats

CVEs Like This One

CVE-2018-0154Same product: Cisco 1000 Integrated Services Routerboth on KEV
CVE-2018-0180Same product: Cisco 1000 Integrated Services Routerboth on KEV
CVE-2018-0179Same product: Cisco 1000 Integrated Services Routerboth on KEV
CVE-2017-12237Same product: Cisco 1000 Integrated Services Routerboth on KEV
CVE-2017-12231Same product: Cisco 1100-4G\/6G Integrated Services Routerboth on KEV
CVE-2018-0161Same product: Cisco Iosboth on KEV
CVE-2017-12238Same product: Cisco Iosboth on KEV
CVE-2022-20775Same product: Cisco 1100-4G Integrated Services Routerboth on KEV
CVE-2017-12319Same product: Cisco 1000 Integrated Services Routerboth on KEV
CVE-2017-6627Same product: Cisco Iosboth on KEV

Affected Assets

cisco
ios
15.0 — 15.6

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References