Cyber Resilience

CVE-2017-12238

Cisco Ios 15.0 – 15.4

CISA KEVActive ExploitationEUVD Exploited
Published
29 September 2017
Modified
21 April 2026
KEV Added
03 March 2022
Patch / advisory
CVSS Score v3.1 6.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score 0.020 79th percentile
Risk Priority 76 floored blend · peak EPSS

Summary

CVE-2017-12238 is a medium-severity an unspecified weakness vulnerability in Cisco Catalyst 6000 Ws-Svc-Nam-1. Its CVSS base score is 6.5 (Medium).

Operationally, ranked in the top 21% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

A vulnerability exists in the Virtual Private LAN Service (VPLS) implementation within Cisco IOS versions 15.0 through 15.4 running on Catalyst 6800 Series Switches. The flaw is a memory management issue that occurs when handling VPLS-generated MAC address entries. It affects devices equipped with a C6800-16P10G or C6800-16P10G-XL line card paired with Supervisor Engine 6T, where the line card serves as a core-facing MPLS interface and VPLS is enabled.

An unauthenticated attacker with adjacent network access can exploit the issue by generating a large volume of VPLS MAC entries. Successful exploitation causes the affected line card to crash, producing a denial-of-service condition on the switch. The CVSS score of 6.5 reflects the attack vector and high availability impact with no privileges or user interaction required.

The Cisco Security Advisory cisco-sa-20170927-vpls, along with associated Bug ID CSCva61927, provides official guidance on affected releases and remediation steps. No information is available regarding observed in-the-wild exploitation.

EU & UK References

Vulnerability Data

A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting…

more

in a denial of service (DoS) condition. The vulnerability is due to a memory management issue in the affected software. An attacker could exploit this vulnerability by creating a large number of VPLS-generated MAC entries in the MAC address table of an affected device. A successful exploit could allow the attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a DoS condition. This vulnerability affects Cisco Catalyst 6800 Series Switches that are running a vulnerable release of Cisco IOS Software and have a Cisco C6800-16P10G or C6800-16P10G-XL line card in use with Supervisor Engine 6T. To be vulnerable, the device must also be configured with VPLS and the C6800-16P10G or C6800-16P10G-XL line card needs to be the core-facing MPLS interfaces. Cisco Bug IDs: CSCva61927.

CWE(s)
KEV Date Added
03 March 2022

Related Threats

CVEs Like This One

CVE-2018-0161Same product: Cisco Iosboth on KEV
CVE-2017-12232Same product: Cisco Iosboth on KEV
CVE-2018-0154Same product: Cisco Iosboth on KEV
CVE-2018-0180Same product: Cisco Iosboth on KEV
CVE-2018-0179Same product: Cisco Iosboth on KEV
CVE-2017-12237Same product: Cisco Iosboth on KEV
CVE-2017-12231Same product: Cisco Iosboth on KEV
CVE-2017-6627Same product: Cisco Iosboth on KEV
CVE-2018-0156Same product: Cisco Iosboth on KEV
CVE-2016-6366Same product: Cisco Catalyst 6500both on KEV

Affected Assets

cisco
ios
15.0 — 15.4

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References