LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-12238: Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-12238 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a denial of service.

CVE-2017-12238 is a denial-of-service vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS on Cisco Catalyst 6800 Series Switches. An unauthenticated attacker on an adjacent network segment could trigger it and disrupt switch availability. For teams running these platforms in campus or data-center fabrics, loss of a Catalyst 6800 can interrupt VPLS-based Layer-2 services and the traffic that depends on them.

Because the flaw requires only adjacent reachability and no credentials, it matters wherever VPLS is enabled on these switches. Confirm exact impact and fixed software against the vendor advisory before prioritizing remediation.

How it works

The weakness is classified as CWE-399 (Resource Management Errors). In the VPLS implementation inside Cisco IOS on the Catalyst 6800 Series, improper handling of certain protocol conditions can exhaust or corrupt internal resources that the switch needs to keep the VPLS process stable.

An unauthenticated, adjacent attacker sends crafted traffic that reaches the VPLS code path. The switch fails to manage the associated resources correctly, leading to a denial-of-service condition that can halt or severely degrade VPLS forwarding. No remote unauthenticated exploitation across Layer-3 boundaries is described; adjacency is required. Specific packet formats and exact failure modes are not detailed in the public summary and must be taken from the vendor advisory.

Am I affected? How to find it in your systems

Cisco Catalyst 6800 Series Switches running Cisco IOS with VPLS configured are the only platforms named. These chassis commonly appear as core or aggregation switches in enterprise campus and data-center networks that extend Layer-2 domains across sites via VPLS.

How to remediate

Patch first. Apply the Cisco IOS updates identified in the vendor advisory for CVE-2017-12238 on every affected Catalyst 6800. Follow Cisco’s published installation and reload procedures, and verify the new image with “show version” after the change.

After patching, reduce the attack surface for similar resource-management issues:

If you can't patch immediately

Until the vendor update can be deployed, apply compensating controls that limit adjacency and visibility of the VPLS service:

These steps only reduce risk; they do not eliminate the underlying resource-management flaw. Schedule the official patch as soon as operationally feasible.

If your data may have been exposed

This vulnerability is a denial-of-service issue; the public record does not document data exfiltration or ransomware use. Nevertheless, any successfully exploited denial-of-service condition can be a precursor to broader compromise if an attacker gains a foothold elsewhere. If you suspect your environment was targeted, review adjacent-network logs and device crashinfo files, and consider standard incident-response steps. You can also run a free exposure scan of your email addresses against known breach data sets to check whether credentials or personal information have appeared in prior unrelated incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Catalyst 6800 Series Switches
WeaknessCWE-399
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 24, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities