First published: Fri Feb 03 2017(Updated: )
A vulnerability in the implementation of Common Industrial Protocol (CIP) functionality in Cisco Industrial Ethernet 2000 Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to a system memory leak. More Information: CSCvc54788. Known Affected Releases: 15.2(5.4.32i)E2. Known Fixed Releases: 15.2(5.4.62i)E2.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Industrial Ethernet 2000 Series Firmware | <=15.2\(5.4.32i\)e2 | |
Cisco IE 2000 Industrial Ethernet Switch | ||
Cisco Industrial Ethernet 2000 16ptc-g-l Switch | ||
Cisco Industrial Ethernet 2000 16ptc-g-nx Switch | ||
Cisco IE 2000-16t67 Industrial Ethernet switch | ||
Cisco Industrial Ethernet 2000 16t67p-g-e Switch | ||
Cisco IE 2000-16tc-g-e Industrial Ethernet switch | ||
Cisco IE 2000-16tc Industrial Ethernet Switch | ||
Cisco IE 2000-16tc-g-n Industrial Ethernet switch | ||
Cisco IE 2000-16tc-g-x Industrial Ethernet switch | ||
Cisco Industrial Ethernet 2000 16tc-l Switch | ||
Cisco IE 2000-24t67 Industrial Ethernet switch | ||
Cisco Industrial Ethernet 2000 4s-ts-g-b Switch | ||
Cisco Industrial Ethernet 2000 4s-ts-g-l Switch | ||
Cisco IE 2000 Series Industrial Ethernet Switch | ||
Cisco Industrial Ethernet 2000 4t-g-b Switch | ||
Cisco Industrial Ethernet 2000 4t-g-l Switch | ||
Cisco IE 2000-4t Industrial Ethernet switch | ||
Cisco IE 2000 Series Industrial Ethernet Switch | ||
Cisco Industrial Ethernet 2000 4s-ts-g-b Switch | ||
Cisco Industrial Ethernet 2000 4ts-g-l Switch | ||
Cisco IE 2000 Industrial Ethernet Switch | ||
Cisco Industrial Ethernet 2000 8t67-b Switch | ||
Cisco Industrial Ethernet 2000 8t67p-g-e Switch | ||
Cisco Industrial Ethernet 2000 8tc-b Switch | ||
Cisco Industrial Ethernet 2000 8tc-g-b Switch | ||
Cisco IE 2000-8TC-G-E | ||
Cisco Industrial Ethernet 2000 8tc-g-l Switch | ||
Cisco IE 2000-8tc-g-n Industrial Ethernet switch | ||
Cisco Industrial Ethernet 2000 8tc-l Switch |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3812 is classified as a medium severity vulnerability allowing potential denial of service.
To mitigate CVE-2017-3812, you should upgrade the firmware of the affected Cisco Industrial Ethernet 2000 Series Switches to a version higher than 15.2(5.4.32i)e2.
The denial of service in CVE-2017-3812 is caused by a memory leak in the Common Industrial Protocol (CIP) functionality.
CVE-2017-3812 affects users of Cisco Industrial Ethernet 2000 Series Switches running specific vulnerable firmware versions.
Yes, CVE-2017-3812 can be exploited by an unauthenticated remote attacker.