CVE-2017-12232 — Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability

CVE-2017-12232

Cisco IOS on ISR G2 — Adjacent-Network Protocol Flaw Causes Device Reload; September 2017 Advisory Bundle; Nation-State Network Infrastructure Targeting

What Is Cisco IOS?

Cisco Integrated Services Routers Generation 2 (ISR G2) are mid-range branch office and WAN access routers running Cisco IOS, widely deployed for connecting remote offices and branch networks to enterprise WAN infrastructure. ISR G2 routers handle business-critical connectivity for enterprise and government networks. As with all Cisco IOS devices, ISR G2 routers are subject to network-accessible DoS vulnerabilities that can disrupt connectivity when exploited.

Overview

Actively Exploited. This vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) Catalog on March 3, 2022. Federal agencies are required to apply mitigations per BOD 22-01.

CVE-2017-12232 is a denial-of-service vulnerability in Cisco IOS running on Cisco Integrated Services Routers Generation 2 (ISR G2). An unauthenticated attacker on the same network segment (adjacent network, AV:A) can trigger a device reload by sending specially crafted protocol packets to an affected device. Patched in the Cisco September 2017 advisory bundle. CISA added CVE-2017-12232 to the KEV catalog in March 2022 as part of a batch of Cisco IOS vulnerabilities confirmed in exploitation by nation-state actors targeting US critical infrastructure networks.

Affected Versions

Cisco ISR G2 devices (ISR 1900, 2900, 3900 series) running affected Cisco IOS versions. Consult cisco-sa-20170929-isr and the Cisco IOS Software Checker for specific affected version details.

Technical Details

Root Cause: Resource Management Flaw in ISR G2 Protocol Handler

CVE-2017-12232 is a resource management vulnerability (CWE-399) in the Cisco IOS implementation on ISR G2 hardware. A crafted protocol message sent from the adjacent network segment triggers an error condition in the IOS protocol handler that is not properly managed, causing a process crash and device reload. The AV:A (Adjacent Vector) attack vector means the attacker must be able to send layer-2 or layer-3 traffic directly reachable to the target device's interfaces — the attack does not traverse arbitrary network hops.

Why adjacent-vector DoS matters: Nation-state actors who have already gained access to an internal network segment (via a compromised internal host or physical access) can use AV:A vulnerabilities to disrupt network infrastructure from within the perimeter, complicating incident response and potentially disrupting monitoring infrastructure.

Attack Characteristics

Attribute Detail
Attack Vector Adjacent — same network segment
Affected Hardware Cisco ISR G2 (1900, 2900, 3900 series)
Impact Device reload → connectivity disruption

Discovery

Reported to Cisco through coordinated disclosure; patched in September 2017 advisory bundle.

Exploitation Context

  • Part of March 2022 KEV batch: CVE-2017-12232 was added to KEV alongside 8 other Cisco IOS CVEs from the same September 2017 advisory bundle, reflecting CISA's assessment that nation-state actors exploiting Cisco infrastructure vulnerabilities represents an ongoing threat to US critical infrastructure
  • Branch network targeting: ISR G2 routers are common at branch offices and remote sites; disrupting a branch router cuts off connectivity for that site's users and systems

Remediation

CISA BOD 22-01 Deadline: March 24, 2022. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
  1. Apply Cisco IOS security update — identify affected IOS versions via the Cisco IOS Software Checker using advisory cisco-sa-20170929-isr, then upgrade to the fixed IOS release.

  2. Restrict adjacent-network access — implement port security and 802.1X authentication on switch ports connected to ISR G2 devices; restrict which hosts can send traffic to the router's interfaces.

  3. Maintain IOS patch currency — establish a regular patching cadence for all Cisco IOS devices; apply security updates during planned maintenance windows.

Key Details

PropertyValue
CVE ID CVE-2017-12232
Vendor / Product Cisco — IOS software
NVD Published2017-09-29
NVD Last Modified2026-01-12
CVSS 3.1 Score6.5
CVSS 3.1 VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
SeverityMEDIUM
CWE CWE-399 — Resource Management Errors find similar ↗
CISA KEV Added2022-03-03
CISA KEV Deadline2022-03-24
Known Ransomware Use No

CVSS 3.1 Breakdown

Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Required Action

CISA BOD 22-01 Deadline: 2022-03-24. Apply updates per vendor instructions.

Timeline

DateEvent
2017-09-27Cisco releases September 2017 security advisory bundle patching CVE-2017-12232
2017-09-29CVE-2017-12232 published by NVD
2022-03-03Added to CISA Known Exploited Vulnerabilities catalog
2022-03-24CISA BOD 22-01 remediation deadline

References

ResourceType
NVD — CVE-2017-12232 Vulnerability Database
CISA KEV Catalog Entry US Government
Cisco Security Advisory cisco-sa-20170929-isr Vendor Advisory