Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-12319


A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability. The vulnerability exists due to changes in the implementation of the BGP MPLS-Based Ethernet VPN RFC (RFC 7432) draft between IOS XE software releases. When the BGP Inclusive Multicast Ethernet Tag Route or BGP EVPN MAC/IP Advertisement Route update packet is received, it could be possible that the IP address length field is miscalculated. An attacker could exploit this vulnerability by sending a crafted BGP packet to an affected device after the BGP session was established. An exploit could allow the attacker to cause the affected device to reload or corrupt the BGP routing table; either outcome would result in a DoS. The vulnerability may be triggered when the router receives a crafted BGP message from a peer on an existing BGP session. This vulnerability affects all releases of Cisco IOS XE Software prior to software release 16.3 that support BGP EVPN configurations. If the device is not configured for EVPN, it is not vulnerable. Cisco Bug IDs: CSCui67191, CSCvg52875.


Published

2018-03-27T09:29:00.280

Last Modified

2025-01-27T19:13:34.663

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:N/A:C

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

8.6

Impact Score

6.9

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco ios 15.4\(1\)s Yes
Operating System cisco ios_xe < 16.3 Yes
Hardware cisco 1000_integrated_services_router - No
Hardware cisco 1100-4g\/6g_integrated_services_router - No
Hardware cisco 1100-4g_integrated_services_router - No
Hardware cisco 1100-4gltegb_integrated_services_router - No
Hardware cisco 1100-4gltena_integrated_services_router - No
Hardware cisco 1100-4p_integrated_services_router - No
Hardware cisco 1100-6g_integrated_services_router - No
Hardware cisco 1100-8p_integrated_services_router - No
Hardware cisco 1100-lte_integrated_services_router - No
Hardware cisco 1100_integrated_services_router - No
Hardware cisco 1101-4p_integrated_services_router - No
Hardware cisco 1101_integrated_services_router - No
Hardware cisco 1109-2p_integrated_services_router - No
Hardware cisco 1109-4p_integrated_services_router - No
Hardware cisco 1109_integrated_services_router - No
Hardware cisco 1111x-8p_integrated_services_router - No
Hardware cisco 1111x_integrated_services_router - No
Hardware cisco 111x_integrated_services_router - No
Hardware cisco 1120_integrated_services_router - No
Hardware cisco 1131_integrated_services_router - No
Hardware cisco 1160_integrated_services_router - No
Hardware cisco 1801_integrated_service_router - No
Hardware cisco 1802_integrated_service_router - No
Hardware cisco 1803_integrated_service_router - No
Hardware cisco 1811_integrated_service_router - No
Hardware cisco 1812_integrated_service_router - No
Hardware cisco 1841_integrated_service_router - No
Hardware cisco 1861_integrated_service_router - No
Hardware cisco 1905_integrated_services_router - No
Hardware cisco 1906c_integrated_services_router - No
Hardware cisco 1921_integrated_services_router - No
Hardware cisco 1941_integrated_services_router - No
Hardware cisco 1941w_integrated_services_router - No
Hardware cisco 4000_integrated_services_router - No
Hardware cisco 422_integrated_services_router - No
Hardware cisco 4221_integrated_services_router - No
Hardware cisco 4321\/k9-rf_integrated_services_router - No
Hardware cisco 4321\/k9-ws_integrated_services_router - No
Hardware cisco 4321\/k9_integrated_services_router - No
Hardware cisco 4321_integrated_services_router - No
Hardware cisco 4331\/k9-rf_integrated_services_router - No
Hardware cisco 4331\/k9-ws_integrated_services_router - No
Hardware cisco 4331\/k9_integrated_services_router - No
Hardware cisco 4331_integrated_services_router - No
Hardware cisco 4351\/k9-rf_integrated_services_router - No
Hardware cisco 4351\/k9-ws_integrated_services_router - No
Hardware cisco 4351\/k9_integrated_services_router - No
Hardware cisco 4351_integrated_services_router - No
Hardware cisco 4431_integrated_services_router - No
Hardware cisco 44461_integrated_services_router - No
Hardware cisco 4451-x_integrated_services_router - No
Hardware cisco 4451_integrated_services_router - No
Hardware cisco 4461_integrated_services_router - No
Hardware cisco 8101-32fh - No
Hardware cisco 8101-32h - No
Hardware cisco 8102-64h - No
Hardware cisco 8201 - No
Hardware cisco 8201-32fh - No
Hardware cisco 8202 - No
Hardware cisco 8208 - No
Hardware cisco 8212 - No
Hardware cisco 8218 - No
Hardware cisco 8800_12-slot - No
Hardware cisco 8800_18-slot - No
Hardware cisco 8800_4-slot - No
Hardware cisco 8800_8-slot - No
Hardware cisco 8804 - No
Hardware cisco 8808 - No
Hardware cisco 8812 - No
Hardware cisco 8818 - No
Hardware cisco 8831 - No
Hardware cisco 9800-40 - No
Hardware cisco 9800-80 - No
Hardware cisco 9800-cl - No
Hardware cisco 9800-l - No
Hardware cisco asr_1000 - No
Hardware cisco asr_1000-esp100 - No
Hardware cisco asr_1000-esp100-x - No
Hardware cisco asr_1000-esp200-x - No
Hardware cisco asr_1000-x - No
Hardware cisco asr_1001 - No
Hardware cisco asr_1001-hx - No
Hardware cisco asr_1001-hx_r - No
Hardware cisco asr_1001-x - No
Hardware cisco asr_1001-x_r - No
Hardware cisco asr_1002 - No
Hardware cisco asr_1002-hx - No
Hardware cisco asr_1002-hx_r - No
Hardware cisco asr_1002-x - No
Hardware cisco asr_1002-x_r - No
Hardware cisco asr_1004 - No
Hardware cisco asr_1006 - No
Hardware cisco asr_1006-x - No
Hardware cisco asr_1009-x - No
Hardware cisco asr_1013 - No
Hardware cisco asr_1023 - No
Hardware cisco asr_900 - No
Hardware cisco asr_901-12c-f-d - No
Hardware cisco asr_901-12c-ft-d - No
Hardware cisco asr_901-4c-f-d - No
Hardware cisco asr_901-4c-ft-d - No
Hardware cisco asr_901-6cz-f-a - No
Hardware cisco asr_901-6cz-f-d - No
Hardware cisco asr_901-6cz-fs-a - No
Hardware cisco asr_901-6cz-fs-d - No
Hardware cisco asr_901-6cz-ft-a - No
Hardware cisco asr_901-6cz-ft-d - No
Hardware cisco asr_901s-2sg-f-ah - No
Hardware cisco asr_901s-2sg-f-d - No
Hardware cisco asr_901s-3sg-f-ah - No
Hardware cisco asr_901s-3sg-f-d - No
Hardware cisco asr_901s-4sg-f-d - No
Hardware cisco asr_902 - No
Hardware cisco asr_902u - No
Hardware cisco catalyst_8200 - No
Hardware cisco catalyst_8300 - No
Hardware cisco catalyst_8300-1n1s-4t2x - No
Hardware cisco catalyst_8300-1n1s-6t - No
Hardware cisco catalyst_8300-2n2s-4t2x - No
Hardware cisco catalyst_8300-2n2s-6t - No
Hardware cisco catalyst_8500 - No
Hardware cisco catalyst_8500-4qc - No
Hardware cisco catalyst_8500l - No
Hardware cisco catalyst_8510csr - No
Hardware cisco catalyst_8510msr - No
Hardware cisco catalyst_8540csr - No
Hardware cisco catalyst_8540msr - No
Hardware cisco catalyst_9200 - No
Hardware cisco catalyst_9200cx - No
Hardware cisco catalyst_9200l - No
Hardware cisco catalyst_9300 - No
Hardware cisco catalyst_9300-24p-a - No
Hardware cisco catalyst_9300-24p-e - No
Hardware cisco catalyst_9300-24s-a - No
Hardware cisco catalyst_9300-24s-e - No
Hardware cisco catalyst_9300-24t-a - No
Hardware cisco catalyst_9300-24t-e - No
Hardware cisco catalyst_9300-24u-a - No
Hardware cisco catalyst_9300-24u-e - No
Hardware cisco catalyst_9300-24ux-a - No
Hardware cisco catalyst_9300-24ux-e - No
Hardware cisco catalyst_9300-48p-a - No
Hardware cisco catalyst_9300-48p-e - No
Hardware cisco catalyst_9300-48s-a - No
Hardware cisco catalyst_9300-48s-e - No
Hardware cisco catalyst_9300-48t-a - No
Hardware cisco catalyst_9300-48t-e - No
Hardware cisco catalyst_9300-48u-a - No
Hardware cisco catalyst_9300-48u-e - No
Hardware cisco catalyst_9300-48un-a - No
Hardware cisco catalyst_9300-48un-e - No
Hardware cisco catalyst_9300-48uxm-a - No
Hardware cisco catalyst_9300-48uxm-e - No
Hardware cisco catalyst_9300l - No
Hardware cisco catalyst_9300l-24p-4g-a - No
Hardware cisco catalyst_9300l-24p-4g-e - No
Hardware cisco catalyst_9300l-24p-4x-a - No
Hardware cisco catalyst_9300l-24p-4x-e - No
Hardware cisco catalyst_9300l-24t-4g-a - No
Hardware cisco catalyst_9300l-24t-4g-e - No
Hardware cisco catalyst_9300l-24t-4x-a - No
Hardware cisco catalyst_9300l-24t-4x-e - No
Hardware cisco catalyst_9300l-48p-4g-a - No
Hardware cisco catalyst_9300l-48p-4g-e - No
Hardware cisco catalyst_9300l-48p-4x-a - No
Hardware cisco catalyst_9300l-48p-4x-e - No
Hardware cisco catalyst_9300l-48t-4g-a - No
Hardware cisco catalyst_9300l-48t-4g-e - No
Hardware cisco catalyst_9300l-48t-4x-a - No
Hardware cisco catalyst_9300l-48t-4x-e - No
Hardware cisco catalyst_9300l_stack - No
Hardware cisco catalyst_9300lm - No
Hardware cisco catalyst_9300x - No
Hardware cisco catalyst_9400 - No
Hardware cisco catalyst_9400_supervisor_engine-1 - No
Hardware cisco catalyst_9407r - No
Hardware cisco catalyst_9410r - No
Hardware cisco catalyst_9500 - No
Hardware cisco catalyst_9500h - No
Hardware cisco catalyst_9600 - No
Hardware cisco catalyst_9600_supervisor_engine-1 - No
Hardware cisco catalyst_9600x - No
Hardware cisco catalyst_9800 - No
Hardware cisco catalyst_9800-40 - No
Hardware cisco catalyst_9800-80 - No
Hardware cisco catalyst_9800-cl - No
Hardware cisco catalyst_9800-l - No
Hardware cisco catalyst_9800-l-c - No
Hardware cisco catalyst_9800-l-f - No
Hardware cisco catalyst_ie3200_rugged_switch - No
Hardware cisco catalyst_ie3300_rugged_switch - No
Hardware cisco cloud_services_router_1000v - No
Hardware cisco esr-6300-con-k9 - No
Hardware cisco esr-6300-ncp-k9 - No
Hardware cisco integrated_services_virtual_router - No
Hardware cisco network_convergence_system_520 - No

References