LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-12231: Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-12231 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS could allow an unauthenticated, remote attacker to cause a denial of service.

CVE-2017-12231 is a denial-of-service vulnerability in the Network Address Translation (NAT) functionality of Cisco IOS software. An unauthenticated remote attacker could trigger it to disrupt affected devices, which often sit at critical points in enterprise and service-provider networks. Because NAT is commonly enabled on edge routers and firewalls, a successful attack can interrupt connectivity for many users or services until the device is recovered. Confirm exact impact and fixed releases against the vendor advisory.

How it works

The weakness is classified as CWE-399 (resource management errors). In products that implement NAT, the device must track and translate address and port state for traffic flowing through it. When that state-handling logic contains a flaw, carefully crafted or high-volume traffic that exercises the NAT path can exhaust or corrupt internal resources. An attacker who can send packets to an interface where NAT is active may therefore force the device into a condition that requires a reload or otherwise stops forwarding, producing a denial of service. No authentication is required. Specific packet formats, trigger conditions, and exact failure modes are not detailed in the public summary; treat any deeper technical claims as unverified until checked against Cisco’s advisory.

Am I affected? How to find it in your systems

Cisco IOS runs on a wide range of routers, switches, and other network appliances. NAT is frequently configured on Internet edge, DMZ, and remote-access devices. Inventory steps:

Telemetry signs of exploitation are generic for this class: unexpected device reloads, NAT-related traceback or error messages in logs, sudden spikes in CPU or memory associated with the NAT process, or loss of forwarding on NAT-enabled interfaces. Correlate such events with unusual inbound traffic patterns. Absence of these signs does not prove the device is unexploited; confirm patch status directly.

How to remediate

Patching is the primary remediation. Apply the Cisco IOS software updates identified in the vendor advisory for CVE-2017-12231, following Cisco’s installation and reload guidance. CISA’s required action is to apply updates per vendor instructions. After upgrading:

If you can't patch immediately

Until the vendor update can be deployed, reduce exposure with compensating controls:

These measures lower likelihood and impact but do not eliminate the vulnerability; schedule the official patch as soon as possible.

If your data may have been exposed

This CVE is a denial-of-service issue; the public summary does not describe confidentiality impact or data exfiltration. Actively exploited vulnerabilities can still be used as a foothold or distraction in larger incidents, and ransomware use is not documented for this CVE. If you suspect compromise of surrounding systems, follow normal incident-response procedures, preserve logs, and rotate credentials where appropriate. You can also run a free exposure scan of your email addresses against known breach data sets to check whether related accounts appear in unrelated breaches.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · IOS software
WeaknessCWE-399
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 24, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities