CVE-2017-12235: Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability
A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to the improper parsing of ingress PN-DCP Identify Request packets destined to an affected device. An attacker could exploit this vulnerability by sending a crafted PN-DCP Identify Request packet to an affected device and then continuing to send normal PN-DCP Identify Request packets to the device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. This vulnerability affects Cisco devices that are configured to process PROFINET messages. Beginning with Cisco IOS Software Release 12.2(52)SE, PROFINET is enabled by default on all the base switch module and expansion-unit Ethernet ports. Cisco Bug IDs: CSCuz47179.
Other sources
A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco IOSto a version that resolves this vulnerability.Fixed in 12.2(52)SE - Configuration
Disable PROFINET on base switch module and expansion-unit Ethernet ports if not required, since beginning with Cisco IOS Software Release 12.2(52)SE PROFINET is enabled by default on all such ports.
Cisco IOS PROFINET PROFINET (PN-DCP) processing on Ethernet ports = disable if not required - Compensating control
If you cannot immediately disable PROFINET processing, restrict network access to the affected devices so unauthenticated remote attackers cannot reach PN-DCP (e.g., limit which hosts can send PN-DCP Identify Request packets to the devices).
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12235?
CVE-2017-12235 has been classified as a high severity vulnerability due to its potential to cause a denial of service condition.
How do I fix CVE-2017-12235?
To mitigate CVE-2017-12235, you should upgrade to the latest version of Cisco IOS software that includes the necessary patches.
Which devices are affected by CVE-2017-12235?
CVE-2017-12235 affects various versions of Cisco IOS ranging from 12.2 to 15.6.
Can CVE-2017-12235 be exploited remotely?
Yes, an unauthenticated remote attacker can exploit CVE-2017-12235 to trigger a device reload.
What is the potential impact of CVE-2017-12235 on network devices?
The exploitation of CVE-2017-12235 can result in a denial of service condition, impacting the availability of network services.