CVE Feed

    Dashboard / CVE / CVE-2017-12235

    CVE-2017-12235

    A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to the improper parsing of ingress PN-DCP Identify Request packets destined to an affected device. An attacker could exploit this vulnerability by sending a crafted PN-DCP Identify Request packet to an affected device and then continuing to send normal PN-DCP Identify Request packets to the device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. This vulnerability affects Cisco devices that are configured to process PROFINET messages. Beginning with Cisco IOS Software Release 12.2(52)SE, PROFINET is enabled by default on all the base switch module and expansion-unit Ethernet ports. Cisco Bug IDs: CSCuz47179.

    Published:Sep 28, 2017
    Last Modified:Apr 21, 2026
    EPS:Sep 28, 2017
    EPSS Score:0.04928
    CVSS Score:7.5

    CISA Notification

    Description

    A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to the improper parsing of ingress PN-DCP Identify Request packets destined to an affected device. An attacker could exploit this vulnerability by sending a crafted PN-DCP Identify Request packet to an affected device and then continuing to send normal PN-DCP Identify Request packets to the device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. This vulnerability affects Cisco devices that are configured to process PROFINET messages. Beginning with Cisco IOS Software Release 12.2(52)SE, PROFINET is enabled by default on all the base switch module and expansion-unit Ethernet ports. Cisco Bug IDs: CSCuz47179.

    Required Action:

    Apply updates per vendor instructions.

    Notes:

    No extra notes provided.

    Due Date
    Mar 24, 2022
    1632 days ago
    Alert Date
    Mar 3, 2022
    1653 days ago

    Affected Products

    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 16ptc-g-e Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 16ptc-g-l Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 16ptc-g-nx Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 16t67-b Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 16t67p-g-e Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 16tc-g-e Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 16tc-g-l Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 16tc-g-n Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 16tc-g-x Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 16tc-l Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 24t67-b Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 4s-ts-g-b Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 4s-ts-g-l Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 4t-b Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 4t-g-b Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 4t-g-l Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 4t-l Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 4ts-b Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 4ts-g-b Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 4ts-g-l Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 4ts-l Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 8t67-b Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 8t67p-g-e Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 8tc-b Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 8tc-g-b Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 8tc-g-e Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 8tc-g-l Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 8tc-g-n Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 8tc-l Switch
    Vendor
    Cisco
    Product
    Industrial Ethernet 2000 Series Firmware
    Vendor
    Cisco
    Product
    Ios

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High