CVE-2017-12319
Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability
Description
CVE-2017-12319 is a denial-of-service vulnerability in Cisco IOS XE Software. A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability. Successful exploitation could result in denial of service through device reloads on affected devices. CISA has added CVE-2017-12319 to the Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The EPSS score of 0.94% (76.0th percentile) indicates a measurable likelihood of exploitation activity.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| cisco | ios | 15.4\(1\)s |
| cisco | ios xe | < 16.3 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
References
- http://www.securityfocus.com/bid/101676(Broken Link, Third Party Advisory, VDB Entry)
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171103-bgp(Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-12319(US Government Resource)
Weakness Type
CWE-20: Improper Input Validation
Improper Input Validation is a software weakness where a product receives input or data but does not validate or incorrectly validates that the input has the properties required to process data safely and correctly. This vulnerability occurs when applications accept user-supplied data without verifying that it conforms to expected formats, lengths, types, or ranges.
Learn more: CWE-20 — Improper Input Validation
Impact Analysis
CVE-2017-12319 threatens the availability of Cisco IOS XE Software, as exploitation can cause device reloads, resulting in service disruption. With a CVSS score of 5.9 (MEDIUM) and a network-based attack vector requiring no authentication, the barrier to exploitation is moderate. In enterprise environments, repeated exploitation could cause sustained network outages affecting business operations, communications, and service availability. Network infrastructure devices are high-value targets, and their unavailability can have cascading effects across the organization.
Exploit Maturity
CVE-2017-12319 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming that this vulnerability has been exploited in real-world attacks. The EPSS score of 0.94% (76.0th percentile) indicates a measurable probability of exploitation. Organizations should treat this vulnerability as an active and ongoing threat requiring immediate remediation.
Remediation
- Apply vendor updates immediately as required by CISA KEV: Apply updates per vendor instructions.
- If immediate patching is not possible, implement interim mitigations such as restricting access to the affected BGP EVPN functionality to trusted networks only using access control lists.
- Monitor affected devices for signs of exploitation, including unexpected reloads, unusual network traffic, and anomalous process behavior.
- Ensure network monitoring and alerting is configured to detect denial-of-service conditions affecting the Cisco IOS XE Software infrastructure.
- Maintain up-to-date device configurations and backups to enable rapid recovery if exploitation causes device reloads.
Technical Details
CVE-2017-12319 is a denial-of-service vulnerability in the affected component of Cisco IOS XE Software. The vulnerability allows an unauthenticated remote attacker to cause the device to reload by sending specially crafted BGP update messages. The CVSS v3.1 score of 5.9 reflects high attack complexity, no required privileges, and high impact on availability. The attack vector is network, meaning an attacker must have network connectivity to the affected device.
Frequently Asked Questions
Is CVE-2017-12319 being actively exploited?
Yes. CVE-2017-12319 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation. The EPSS score of 0.94% (76.0th percentile) further indicates a notable likelihood of ongoing exploitation.
What products are affected by CVE-2017-12319?
CVE-2017-12319 affects Cisco IOS XE Software. Specifically, affected products include Cisco Ios, Cisco Ios Xe.
How do I fix CVE-2017-12319?
Apply updates per vendor instructions. If immediate patching is not feasible, apply interim mitigations such as access control restrictions and enhanced monitoring to detect exploitation attempts.
How severe is CVE-2017-12319?
CVE-2017-12319 has a CVSS score of 5.9 (MEDIUM). This is a medium-severity denial-of-service vulnerability that can disrupt network operations. While it does not enable code execution, the availability impact on critical network infrastructure makes timely remediation essential.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.