CVE-2017-3812: Medium severity Cisco Industrial Ethernet 2000 Series Firmware vulnerability
A vulnerability in the implementation of Common Industrial Protocol (CIP) functionality in Cisco Industrial Ethernet 2000 Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to a system memory leak. More Information: CSCvc54788. Known Affected Releases: 15.2(5.4.32i)E2. Known Fixed Releases: 15.2(5.4.62i)E2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco Industrial Ethernet 2000 Series Switches (CIP functionality)to a version that resolves this vulnerability.Fixed in 15.2(5.4.62i)E2Patch CSCvc54788
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3812?
CVE-2017-3812 is classified as a medium severity vulnerability allowing potential denial of service.
How do I fix CVE-2017-3812?
To mitigate CVE-2017-3812, you should upgrade the firmware of the affected Cisco Industrial Ethernet 2000 Series Switches to a version higher than 15.2(5.4.32i)e2.
What causes the denial of service in CVE-2017-3812?
The denial of service in CVE-2017-3812 is caused by a memory leak in the Common Industrial Protocol (CIP) functionality.
Who is affected by CVE-2017-3812?
CVE-2017-3812 affects users of Cisco Industrial Ethernet 2000 Series Switches running specific vulnerable firmware versions.
Can CVE-2017-3812 be exploited remotely?
Yes, CVE-2017-3812 can be exploited by an unauthenticated remote attacker.