MEDIUM · 6.5

CVE-2017-12238

A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800...

Vulnerability Description

A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a denial of service (DoS) condition. The vulnerability is due to a memory management issue in the affected software. An attacker could exploit this vulnerability by creating a large number of VPLS-generated MAC entries in the MAC address table of an affected device. A successful exploit could allow the attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a DoS condition. This vulnerability affects Cisco Catalyst 6800 Series Switches that are running a vulnerable release of Cisco IOS Software and have a Cisco C6800-16P10G or C6800-16P10G-XL line card in use with Supervisor Engine 6T. To be vulnerable, the device must also be configured with VPLS and the C6800-16P10G or C6800-16P10G-XL line card needs to be the core-facing MPLS interfaces. Cisco Bug IDs: CSCva61927.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
CiscoIos>= 15.0, <= 15.4
CiscoC6800-16P10G-
CiscoC6800-16P10G-Xl-
CiscoCatalyst 6000-
CiscoCatalyst 6000 Ws-Svc-Nam-12.2\(1a\)
CiscoCatalyst 6000 Ws-Svc-Nam-22.2\(1a\)
CiscoCatalyst 6000 Ws-X6380-Nam2.1\(2\)
CiscoCatalyst 6500-
CiscoCatalyst 6500-E-
CiscoCatalyst 6500 Ws-Svc-Nam-12.2\(1a\)
CiscoCatalyst 6500 Ws-Svc-Nam-22.2\(1a\)
CiscoCatalyst 6500 Ws-X6380-Nam2.1\(2\)
CiscoCatalyst 6503-E-
CiscoCatalyst 6504-E-
CiscoCatalyst 6506-E-
CiscoCatalyst 6509-E-
CiscoCatalyst 6509-Neb-A-
CiscoCatalyst 6509-V-E-
CiscoCatalyst 6513-
CiscoCatalyst 6513-E-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-12238?

CVE-2017-12238 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800...

How severe is CVE-2017-12238?

CVE-2017-12238 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-12238?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios, Cisco C6800-16P10G, Cisco C6800-16P10G-Xl, Cisco Catalyst 6000, Cisco Catalyst 6000 Ws-Svc-Nam-1.