CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇬🇧 English

CVE-2017-12240

Buffer overflow w DHCP relay Cisco IOS — RCE bez uwierzytelnienia

CVSS 9.8v3.1pub. 2017-09-29upd. 2026-04-21

Podatność buffer overflow w podsystemie DHCP relay w Cisco IOS 12.2–15.6 oraz Cisco IOS XE pozwala zdalnemu, nieuwierzytelnionemu napastnikowi na wykonanie dowolnego kodu i przejęcie pełnej kontroli nad urządzeniem. Podatność jest aktywnie wykorzystywana i widnieje w katalogu CISA KEV.

Pokaż oryginał (EN)

The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system. The attacker could also cause an affected system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to a buffer overflow condition in the DHCP relay subsystem of the affected software. An attacker could exploit this vulnerability by sending a crafted DHCP Version 4 (DHCPv4) packet to an affected system. A successful exploit could allow the attacker to execute arbitrary code and gain full control of the affected system or cause the affected system to reload, resulting in a DoS condition. Cisco Bug IDs: CSCsm45390, CSCuw77959.

🤖 Analiza AI
Jak działa

Błąd wynika z przepełnienia bufora (buffer overflow) w podsystemie DHCP relay w oprogramowaniu Cisco IOS i IOS XE. Atakujący wysyła specjalnie spreparowany pakiet DHCPv4 do podatnego urządzenia, co powoduje przekroczenie granic bufora w pamięci. Skuteczne wykorzystanie tej podatności umożliwia wykonanie dowolnego kodu w kontekście systemu operacyjnego urządzenia lub wymuszenie jego ponownego uruchomienia.

Skutki

Atakujący może uzyskać pełną kontrolę nad urządzeniem (RCE) lub wywołać jego awaryjne przeładowanie, powodując niedostępność usług (DoS). Podatność nie wymaga żadnego uwierzytelnienia ani interakcji użytkownika.

Mitygacja

Należy zastosować patche dostępne u producenta zgodnie z oficjalnym biuletynem bezpieczeństwa Cisco (cisco-sa-20170927-dhcp). Szczegółowe informacje o zalecanych wersjach oprogramowania dostępne są pod adresem https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170927-dhcp. Jeśli aktualizacja nie jest natychmiast możliwa, należy rozważyć ograniczenie dostępu do funkcji DHCP relay na interfejsach sieciowych narażonych na ruch z niezaufanych źródeł.

Kogo dotyczy

Cisco IOS w wersjach 12.2 do 15.6 oraz Cisco IOS XE Software; urządzenia wymienione jako podatne to m.in. Cisco 1000 Integrated Services Router, Cisco 1100-4G ISR, Cisco 1100-4GLTEGB ISR, Cisco 1100-4GLTENA ISR

Uwagi

Podatność zidentyfikowana pod identyfikatorami błędów Cisco: CSCsm45390 oraz CSCuw77959. Biuletyn bezpieczeństwa Cisco opublikowany 27 września 2017 r.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Cisco 1000 Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1100 4g Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1100 4gltegb Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1100 4gltena Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1100 4p Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1100 6g Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1100 8p Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1100 Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1100 Lte Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1101 4p Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1101 Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1109 2p Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1109 4p Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1109 Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1111x 8p Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1111x Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 111x Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1120 Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1131 Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1160 Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1801 Integrated Service Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1802 Integrated Service Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1803 Integrated Service Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1811 Integrated Service Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1812 Integrated Service Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1841 Integrated Service Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1861 Integrated Service Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1905 Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1906c Integrated Services Router

    HW
    Cisco
    wszystkie wersje
  • Cisco 1921 Integrated Services Router

    HW
    Cisco
    wszystkie wersje

CISA KEV — szczegółyi

Dostawcai
Cisco
Produkti
IOS and IOS XE Software
Data dodania do KEVi
3 marca 2022
Termin remediation (USA)i
24 marca 2022(po terminie)
Wymagana akcja (CISA)i

Zastosuj aktualizacje zgodnie z instrukcjami dostawcy.

tłumaczenie AI
Pokaż oryginał (EN)

Apply updates per vendor instructions.

Opis CISAi

Podsystem DHCP relay w oprogramowaniu Cisco IOS i Cisco IOS XE zawiera lukę, która może umożliwić nieuwierzytelnionemu, zdalnemu atakującemu wykonanie dowolnego kodu i uzyskanie pełnej kontroli nad systemem, którego luka dotyczy.

tłumaczenie AI
Pokaż oryginał (EN)

The Dynamic Host Configuration Protocol (DHCP) relay subsystem of Cisco IOS and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system.

🔴
NATYCHMIASTOWE DZIAŁANIE
Aktywnie wykorzystywane w atakach (CISA KEV). Załataj jak najszybciej.
CISA DEADLINE: 24 marca 2022
Tagi
RCEDoSMemory
CWE
Referencje

Powiązane podatności

CVE-2020-3161CRITICAL9.8⚠ KEVPL ✓ten sam produkt

RCE i DoS w serwerze HTTP telefonów Cisco IP Phone

CVE-2018-0171CRITICAL9.8⚠ KEVPL ✓ten sam produkt

RCE i DoS w funkcji Smart Install systemu Cisco IOS przez przepełnienie bufora

CVE-2017-3881CRITICAL9.8⚠ KEVPL ✓ten sam produkt

RCE w Cisco IOS/IOS XE – podatność protokołu CMP przez Telnet

CVE-2025-20363CRITICAL9.0PL ✓ten sam produkt

RCE w web services Cisco ASA, FTD, IOS, IOS XE, IOS XR przez HTTP

CVE-2021-34727CRITICAL9.8PL ✓ten sam produkt

Buffer overflow w procesie vDaemon Cisco IOS XE SD-WAN — RCE z uprawnieniami root