Cyber Resilience

CVE-2017-12237

Cisco Ios 15.0 – 15.6

CISA KEVActive ExploitationEUVD Exploited
Published
29 September 2017
Modified
21 April 2026
KEV Added
03 March 2022
Patch / advisory
CVSS Score v3.1 7.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score 0.071 94th percentile
Risk Priority 84 floored blend · peak EPSS

Summary

CVE-2017-12237 is a high-severity an unspecified weakness vulnerability in Cisco Ios. Its CVSS base score is 7.5 (High).

Operationally, ranked in the top 6% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

The vulnerability CVE-2017-12237 resides in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5. It arises from how affected devices process certain IKEv2 packets and is present on any system with the Internet Security Association and Key Management Protocol (ISAKMP) enabled, regardless of whether IKEv2-specific features are configured. This encompasses devices using LAN-to-LAN VPN, remote-access VPN (excluding SSL VPN), Dynamic Multipoint VPN (DMVPN), or FlexVPN.

An unauthenticated remote attacker can trigger the flaw by sending crafted IKEv2 packets to an exposed device. Successful exploitation produces high CPU utilization, traceback messages, or a reload, resulting in a denial-of-service condition. The issue carries a CVSS 3.1 score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) and is tracked under Cisco Bug ID CSCvc41277.

The referenced Cisco Security Advisory cisco-sa-20170927-ike, along with associated security bulletins, details mitigation steps and available software updates for the affected releases.

EU & UK References

Vulnerability Data

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload…

more

of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to how an affected device processes certain IKEv2 packets. An attacker could exploit this vulnerability by sending specific IKEv2 packets to an affected device to be processed. A successful exploit could allow the attacker to cause high CPU utilization, traceback messages, or a reload of the affected device that leads to a DoS condition. This vulnerability affects Cisco devices that have the Internet Security Association and Key Management Protocol (ISAKMP) enabled. Although only IKEv2 packets can be used to trigger this vulnerability, devices that are running Cisco IOS Software or Cisco IOS XE Software are vulnerable when ISAKMP is enabled. A device does not need to be configured with any IKEv2-specific features to be vulnerable. Many features use IKEv2, including different types of VPNs such as the following: LAN-to-LAN VPN; Remote-access VPN, excluding SSL VPN; Dynamic Multipoint VPN (DMVPN); and FlexVPN. Cisco Bug IDs: CSCvc41277.

CWE(s)
KEV Date Added
03 March 2022

Related Threats

CVEs Like This One

CVE-2018-0180Same product: Cisco 1000 Integrated Services Routerboth on KEV
CVE-2018-0179Same product: Cisco 1000 Integrated Services Routerboth on KEV
CVE-2017-12231Same product: Cisco 1100-4G\/6G Integrated Services Routerboth on KEV
CVE-2018-0154Same product: Cisco 1000 Integrated Services Routerboth on KEV
CVE-2017-12232Same product: Cisco 1000 Integrated Services Routerboth on KEV
CVE-2017-12240Same product: Cisco 1000 Integrated Services Routerboth on KEV
CVE-2017-12319Same product: Cisco 1000 Integrated Services Routerboth on KEV
CVE-2018-0161Same product: Cisco Iosboth on KEV
CVE-2017-12238Same product: Cisco Iosboth on KEV
CVE-2023-20273Same product: Cisco Catalyst 3650both on KEV

Affected Assets

cisco
ios
15.0 — 15.6
cisco
ios xe
3.5.0e — 16.5

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References