LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-12233: Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-12233 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload…

CVE-2017-12233 is a denial-of-service vulnerability in the Common Industrial Protocol (CIP) feature of Cisco IOS software. An unauthenticated remote attacker can send crafted CIP requests that cause an affected device to reload, interrupting network operations until the device recovers.

This matters for environments that rely on Cisco IOS devices for routing, switching, or industrial connectivity. A successful attack can take critical infrastructure offline without needing credentials, so teams should confirm exposure and apply vendor fixes promptly.

How it works

The weakness is classified as CWE-20 (Improper Input Validation). In the CIP implementation within Cisco IOS, the software does not adequately validate certain incoming protocol requests. An attacker who can reach the CIP service on an affected device can send malformed or unexpected CIP traffic. Because validation is insufficient, processing that traffic can trigger a condition that forces the device to reload, producing a denial of service.

No authentication is required. The attack is remote and depends only on network reachability to the CIP feature. Exact packet formats and trigger conditions are not detailed in the public summary; defenders should treat any unauthenticated CIP interaction as potentially abusive and confirm technical specifics against the Cisco advisory.

Am I affected? How to find it in your systems

Cisco IOS software is commonly found on enterprise and industrial routers, switches, and related network appliances. CIP is used in industrial automation and control contexts, so devices bridging IT and operational technology networks are of particular interest.

Inventory steps:

Telemetry and log signs of exploitation attempts may include unexpected device reloads, CIP-related error or exception messages, or spikes in traffic to CIP ports or services from untrusted sources. Correlate reload events with network flows directed at CIP. Absence of clear logs does not rule out attempted abuse; treat unexplained reloads on CIP-enabled devices as suspicious until investigated.

How to remediate

Patch first. Apply the Cisco software updates identified in the vendor advisory for CVE-2017-12233, following Cisco’s installation and verification instructions. CISA’s required action is to apply updates per vendor instructions.

After patching:

If you can't patch immediately

Until the vendor update can be deployed, reduce risk with compensating controls:

These measures lower likelihood and impact but do not replace the official software fix. Schedule patching as soon as operationally feasible and confirm remaining exposure against the Cisco advisory.

If your data may have been exposed

This vulnerability is a denial-of-service issue; public information does not document ransomware use or direct data theft via CVE-2017-12233. Actively exploited vulnerabilities can still be chained into broader incidents that lead to breaches. If you suspect compromise of systems or accounts, follow your incident-response process, preserve logs, and review authentication and access records. You can run a free exposure scan of your email addresses to check whether they appear in known breach data sets and take follow-up steps such as credential resets where appropriate.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · IOS software
WeaknessCWE-20
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 24, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities