LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-12235: Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-12235 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload…

CVE-2017-12235 is a denial-of-service vulnerability in Cisco IOS software on certain Industrial Ethernet switches that implement the PROFINET Discovery and Configuration Protocol (PN-DCP). An unauthenticated remote attacker can trigger a device reload, interrupting industrial network connectivity. For operators of OT and industrial Ethernet environments, this matters because a forced reload can halt production traffic and require manual recovery, even though the flaw is not described as leading to code execution or data theft.

Public detail is limited to the CISA summary and the stated weakness; confirm exact platform coverage, fixed releases, and any configuration prerequisites directly against the vendor advisory before acting.

How it works

The underlying weakness is CWE-20 (Improper Input Validation). In this case the flaw sits in the Cisco IOS implementation of PN-DCP, the protocol used for discovery and basic configuration of PROFINET devices. An attacker who can reach the affected interface sends crafted PN-DCP traffic that the device fails to validate correctly. The malformed input causes the IOS process handling the protocol to fail in a way that forces a reload of the entire device, producing a denial of service.

No authentication is required and the attack is remote, so any network path that allows PN-DCP packets to reach the switch is sufficient. Specific packet formats, ports, or exploit sequences are not provided in the available facts; treat any public proof-of-concept claims with caution and verify behavior only in a lab against the vendor’s description.

Am I affected? How to find it in your systems

The vulnerability affects Cisco IOS software running on Cisco Industrial Ethernet switches that support PROFINET. These devices commonly appear in manufacturing, process-control, and other OT networks where PROFINET is used for I/O and device discovery.

Network telemetry that shows unusual PN-DCP traffic volumes or sources outside the expected engineering workstations can serve as an early indicator, but absence of such traffic does not prove the device is safe.

How to remediate

The primary remediation is to apply the Cisco software updates that address CVE-2017-12235, following the vendor’s installation and verification instructions. CISA’s required action is simply to apply updates per vendor instructions.

If you can't patch immediately

Until the fixed image can be deployed, reduce exposure with compensating controls:

If your data may have been exposed

This vulnerability is described solely as a denial-of-service condition that forces a reload; known ransomware use is not documented. A successful attack would primarily disrupt availability rather than exfiltrate data. Nevertheless, any actively exploited network device can become a foothold for later stages of an intrusion. If you observe unexplained reloads or suspect compromise, follow your incident-response process, preserve crashinfo and logs, and examine adjacent systems. You can also run a free exposure scan of your email addresses to check whether credentials or other data appear in known breach corpora, which helps gauge broader exposure even when the specific CVE does not itself leak information.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · IOS software
WeaknessCWE-20
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 24, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities