7.8

CVE-2017-12231

Warning

A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to the improper translation of H.323 messages that use the Registration, Admission, and Status (RAS) protocol and are sent to an affected device via IPv4 packets. An attacker could exploit this vulnerability by sending a crafted H.323 RAS packet through an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition. This vulnerability affects Cisco devices that are configured to use an application layer gateway with NAT (NAT ALG) for H.323 RAS messages. By default, a NAT ALG is enabled for H.323 RAS messages. Cisco Bug IDs: CSCvc57217.

Data is provided by the National Vulnerability Database (NVD)
CiscoIos Version >= 12.4 <= 15.6
   Cisco1100-4g Integrated Services Router Version-
   Cisco1100-4gltegb Integrated Services Router Version-
   Cisco1100-4gltena Integrated Services Router Version-
   Cisco1100-4p Integrated Services Router Version-
   Cisco1100-6g Integrated Services Router Version-
   Cisco1100-8p Integrated Services Router Version-
   Cisco1100-lte Integrated Services Router Version-
   Cisco1100 Integrated Services Router Version-
   Cisco1100 Terminal Services Gateways Version-
   Cisco1101-4p Integrated Services Router Version-
   Cisco1101 Integrated Services Router Version-
   Cisco1109-2p Integrated Services Router Version-
   Cisco1109-4p Integrated Services Router Version-
   Cisco1109 Integrated Services Router Version-
   Cisco1111x-8p Integrated Services Router Version-
   Cisco111x Integrated Services Router Version-
   Cisco1120 Integrated Services Router Version-
   Cisco1131 Integrated Services Router Version-
   Cisco1160 Integrated Services Router Version-
   Cisco1801 Integrated Service Router Version-
   Cisco1802 Integrated Service Router Version-
   Cisco1803 Integrated Service Router Version-
   Cisco1811 Integrated Service Router Version-
   Cisco1812 Integrated Service Router Version-
   Cisco1841 Integrated Service Router Version-
   Cisco1861 Integrated Service Router Version-
   Cisco1905 Integrated Services Router Version-
   Cisco1906c Integrated Services Router Version-
   Cisco1921 Integrated Services Router Version-
   Cisco1941 Integrated Services Router Version-
   Cisco1941w Integrated Services Router Version-
   Cisco4000 Integrated Services Router Version-
   Cisco4221 Integrated Services Router Version-
   Cisco8101-32fh Version-
   Cisco8101-32h Version-
   Cisco8102-64h Version-
   Cisco8201 Version-
   Cisco8201-32fh Version-
   Cisco8202 Version-
   Cisco8208 Version-
   Cisco8212 Version-
   Cisco8218 Version-
   Cisco8800 12-slot Version-
   Cisco8800 18-slot Version-
   Cisco8800 4-slot Version-
   Cisco8800 8-slot Version-
   Cisco8804 Version-
   Cisco8808 Version-
   Cisco8812 Version-
   Cisco8818 Version-
   Cisco9800-40 Version-
   Cisco9800-80 Version-
   Cisco9800-cl Version-
   Cisco9800-l Version-
   CiscoAsr 1000 Version-
   CiscoAsr 1000-esp100 Version-
   CiscoAsr 1000-esp100-x Version-
   CiscoAsr 1000-esp200-x Version-
   CiscoAsr 1001 Version-
   CiscoAsr 1001-hx Version-
   CiscoAsr 1001-hx R Version-
   CiscoAsr 1001-x Version-
   CiscoAsr 1001-x R Version-
   CiscoAsr 1002-hx Version-
   CiscoAsr 1002-hx R Version-
   CiscoAsr 1002-x Version-
   CiscoAsr 1002-x R Version-
   CiscoAsr 1002 Fixed Router Version-
   CiscoAsr 1004 Version-
   CiscoAsr 1006 Version-
   CiscoAsr 1006-x Version-
   CiscoAsr 1009-x Version-
   CiscoAsr 1013 Version-
   CiscoAsr 1023 Version-
   CiscoAsr 900 Version-
   CiscoAsr 9000 Version-
   CiscoAsr 9000v Version-
   CiscoAsr 9001 Version-
   CiscoAsr 9006 Version-
   CiscoAsr 901-12c-f-d Version-
   CiscoAsr 901-12c-ft-d Version-
   CiscoAsr 901-4c-f-d Version-
   CiscoAsr 901-4c-ft-d Version-
   CiscoAsr 901-6cz-f-a Version-
   CiscoAsr 901-6cz-f-d Version-
   CiscoAsr 901-6cz-fs-a Version-
   CiscoAsr 901-6cz-fs-d Version-
   CiscoAsr 901-6cz-ft-a Version-
   CiscoAsr 901-6cz-ft-d Version-
   CiscoAsr 9010 Version-
   CiscoAsr 9010 Version- HwPlatform-
   CiscoAsr 901s-2sg-f-ah Version-
   CiscoAsr 901s-2sg-f-d Version-
   CiscoAsr 901s-3sg-f-ah Version-
   CiscoAsr 901s-3sg-f-d Version-
   CiscoAsr 901s-4sg-f-d Version-
   CiscoAsr 902 Version-
   CiscoAsr 902u Version-
   CiscoAsr 903 Version-
   CiscoAsr 907 Version-
   CiscoAsr 914 Version-
   CiscoAsr 920-10sz-pd Version-
   CiscoAsr 920-10sz-pd R Version-
   CiscoAsr 920-12cz-a Version-
   CiscoAsr 920-12cz-a R Version-
   CiscoAsr 920-12cz-d Version-
   CiscoAsr 920-12cz-d R Version-
   CiscoAsr 920-12sz-im Version-
   CiscoAsr 920-12sz-im R Version-
   CiscoAsr 920-24sz-im Version-
   CiscoAsr 920-24sz-im R Version-
   CiscoAsr 920-24sz-m Version-
   CiscoAsr 920-24sz-m R Version-
   CiscoAsr 920-24tz-m Version-
   CiscoAsr 920-24tz-m R Version-
   CiscoAsr 920-4sz-a Version-
   CiscoAsr 920-4sz-a R Version-
   CiscoAsr 920-4sz-d Version-
   CiscoAsr 920-4sz-d R Version-
   CiscoAsr 920u-12sz-im Version-
   CiscoAsr 9901 Version-
   CiscoAsr 9902 Version-
   CiscoAsr 9903 Version-
   CiscoAsr 9904 Version-
   CiscoAsr 9906 Version-
   CiscoAsr 9910 Version-
   CiscoAsr 9912 Version-
   CiscoAsr 9920 Version-
   CiscoAsr 9922 Version-
   CiscoCatalyst 3650 Version-
   CiscoCatalyst 3650-12x48fd-e Version-
   CiscoCatalyst 3650-12x48fd-l Version-
   CiscoCatalyst 3650-12x48fd-s Version-
   CiscoCatalyst 3650-12x48uq Version-
   CiscoCatalyst 3650-12x48uq-e Version-
   CiscoCatalyst 3650-12x48uq-l Version-
   CiscoCatalyst 3650-12x48uq-s Version-
   CiscoCatalyst 3650-12x48ur Version-
   CiscoCatalyst 3650-12x48ur-e Version-
   CiscoCatalyst 3650-12x48ur-l Version-
   CiscoCatalyst 3650-12x48ur-s Version-
   CiscoCatalyst 3650-12x48uz Version-
   CiscoCatalyst 3650-12x48uz-e Version-
   CiscoCatalyst 3650-12x48uz-l Version-
   CiscoCatalyst 3650-12x48uz-s Version-
   CiscoCatalyst 3650-24pd Version-
   CiscoCatalyst 3650-24pd-e Version-
   CiscoCatalyst 3650-24pd-l Version-
   CiscoCatalyst 3650-24pd-s Version-
   CiscoCatalyst 3650-24pdm Version-
   CiscoCatalyst 3650-24pdm-e Version-
   CiscoCatalyst 3650-24pdm-l Version-
   CiscoCatalyst 3650-24pdm-s Version-
   CiscoCatalyst 3650-24ps-e Version-
   CiscoCatalyst 3650-24ps-l Version-
   CiscoCatalyst 3650-24ps-s Version-
   CiscoCatalyst 3650-24td-e Version-
   CiscoCatalyst 3650-24td-l Version-
   CiscoCatalyst 3650-24td-s Version-
   CiscoCatalyst 3650-24ts-e Version-
   CiscoCatalyst 3650-24ts-l Version-
   CiscoCatalyst 3650-24ts-s Version-
   CiscoCatalyst 3650-48fd-e Version-
   CiscoCatalyst 3650-48fd-l Version-
   CiscoCatalyst 3650-48fd-s Version-
   CiscoCatalyst 3650-48fq Version-
   CiscoCatalyst 3650-48fq-e Version-
   CiscoCatalyst 3650-48fq-l Version-
   CiscoCatalyst 3650-48fq-s Version-
   CiscoCatalyst 3650-48fqm Version-
   CiscoCatalyst 3650-48fqm-e Version-
   CiscoCatalyst 3650-48fqm-l Version-
   CiscoCatalyst 3650-48fqm-s Version-
   CiscoCatalyst 3650-48fs-e Version-
   CiscoCatalyst 3650-48fs-l Version-
   CiscoCatalyst 3650-48fs-s Version-
   CiscoCatalyst 3650-48pd-e Version-
   CiscoCatalyst 3650-48pd-l Version-
   CiscoCatalyst 3650-48pd-s Version-
   CiscoCatalyst 3650-48pq-e Version-
   CiscoCatalyst 3650-48pq-l Version-
   CiscoCatalyst 3650-48pq-s Version-
   CiscoCatalyst 3650-48ps-e Version-
   CiscoCatalyst 3650-48ps-l Version-
   CiscoCatalyst 3650-48ps-s Version-
   CiscoCatalyst 3650-48td-e Version-
   CiscoCatalyst 3650-48td-l Version-
   CiscoCatalyst 3650-48td-s Version-
   CiscoCatalyst 3650-48tq-e Version-
   CiscoCatalyst 3650-48tq-l Version-
   CiscoCatalyst 3650-48tq-s Version-
   CiscoCatalyst 3650-48ts-e Version-
   CiscoCatalyst 3650-48ts-l Version-
   CiscoCatalyst 3650-48ts-s Version-
   CiscoCatalyst 3650-8x24pd-e Version-
   CiscoCatalyst 3650-8x24pd-l Version-
   CiscoCatalyst 3650-8x24pd-s Version-
   CiscoCatalyst 3650-8x24uq Version-
   CiscoCatalyst 3650-8x24uq-e Version-
   CiscoCatalyst 3650-8x24uq-l Version-
   CiscoCatalyst 3650-8x24uq-s Version-
   CiscoCatalyst 3850 Version-
   CiscoCatalyst 3850-12s-e Version-
   CiscoCatalyst 3850-12s-s Version-
   CiscoCatalyst 3850-12x48u Version-
   CiscoCatalyst 3850-12xs-e Version-
   CiscoCatalyst 3850-12xs-s Version-
   CiscoCatalyst 3850-16xs-e Version-
   CiscoCatalyst 3850-16xs-s Version-
   CiscoCatalyst 3850-24p-e Version-
   CiscoCatalyst 3850-24p-l Version-
   CiscoCatalyst 3850-24p-s Version-
   CiscoCatalyst 3850-24pw-s Version-
   CiscoCatalyst 3850-24s-e Version-
   CiscoCatalyst 3850-24s-s Version-
   CiscoCatalyst 3850-24t-e Version-
   CiscoCatalyst 3850-24t-l Version-
   CiscoCatalyst 3850-24t-s Version-
   CiscoCatalyst 3850-24u Version-
   CiscoCatalyst 3850-24u-e Version-
   CiscoCatalyst 3850-24u-l Version-
   CiscoCatalyst 3850-24u-s Version-
   CiscoCatalyst 3850-24xs Version-
   CiscoCatalyst 3850-24xs-e Version-
   CiscoCatalyst 3850-24xs-s Version-
   CiscoCatalyst 3850-24xu Version-
   CiscoCatalyst 3850-24xu-e Version-
   CiscoCatalyst 3850-24xu-l Version-
   CiscoCatalyst 3850-24xu-s Version-
   CiscoCatalyst 3850-32xs-e Version-
   CiscoCatalyst 3850-32xs-s Version-
   CiscoCatalyst 3850-48f-e Version-
   CiscoCatalyst 3850-48f-l Version-
   CiscoCatalyst 3850-48f-s Version-
   CiscoCatalyst 3850-48p-e Version-
   CiscoCatalyst 3850-48p-l Version-
   CiscoCatalyst 3850-48p-s Version-
   CiscoCatalyst 3850-48pw-s Version-
   CiscoCatalyst 3850-48t-e Version-
   CiscoCatalyst 3850-48t-l Version-
   CiscoCatalyst 3850-48t-s Version-
   CiscoCatalyst 3850-48u Version-
   CiscoCatalyst 3850-48u-e Version-
   CiscoCatalyst 3850-48u-l Version-
   CiscoCatalyst 3850-48u-s Version-
   CiscoCatalyst 3850-48xs Version-
   CiscoCatalyst 3850-48xs-e Version-
   CiscoCatalyst 3850-48xs-f-e Version-
   CiscoCatalyst 3850-48xs-f-s Version-
   CiscoCatalyst 3850-48xs-s Version-
   CiscoCatalyst 3850-nm-2-40g Version-
   CiscoCatalyst 3850-nm-8-10g Version-
   CiscoCatalyst 8200 Version-
   CiscoCatalyst 8300 Version-
   CiscoCatalyst 8300-1n1s-4t2x Version-
   CiscoCatalyst 8300-1n1s-6t Version-
   CiscoCatalyst 8300-2n2s-4t2x Version-
   CiscoCatalyst 8300-2n2s-6t Version-
   CiscoCatalyst 8500 Version-
   CiscoCatalyst 8500-4qc Version-
   CiscoCatalyst 8500l Version-
   CiscoCatalyst 8510csr Version-
   CiscoCatalyst 8510msr Version-
   CiscoCatalyst 8540csr Version-
   CiscoCatalyst 8540msr Version-
   CiscoCatalyst 9200 Version-
   CiscoCatalyst 9200cx Version-
   CiscoCatalyst 9200l Version-
   CiscoCatalyst 9300 Version-
   CiscoCatalyst 9300-24p-a Version-
   CiscoCatalyst 9300-24p-e Version-
   CiscoCatalyst 9300-24s-a Version-
   CiscoCatalyst 9300-24s-e Version-
   CiscoCatalyst 9300-24t-a Version-
   CiscoCatalyst 9300-24t-e Version-
   CiscoCatalyst 9300-24u-a Version-
   CiscoCatalyst 9300-24u-e Version-
   CiscoCatalyst 9300-24ux-a Version-
   CiscoCatalyst 9300-24ux-e Version-
   CiscoCatalyst 9300-48p-a Version-
   CiscoCatalyst 9300-48p-e Version-
   CiscoCatalyst 9300-48s-a Version-
   CiscoCatalyst 9300-48s-e Version-
   CiscoCatalyst 9300-48t-a Version-
   CiscoCatalyst 9300-48t-e Version-
   CiscoCatalyst 9300-48u-a Version-
   CiscoCatalyst 9300-48u-e Version-
   CiscoCatalyst 9300-48un-a Version-
   CiscoCatalyst 9300-48un-e Version-
   CiscoCatalyst 9300-48uxm-a Version-
   CiscoCatalyst 9300-48uxm-e Version-
   CiscoCatalyst 9300l Version-
   CiscoCatalyst 9300l-24p-4g-a Version-
   CiscoCatalyst 9300l-24p-4g-e Version-
   CiscoCatalyst 9300l-24p-4x-a Version-
   CiscoCatalyst 9300l-24p-4x-e Version-
   CiscoCatalyst 9300l-24t-4g-a Version-
   CiscoCatalyst 9300l-24t-4g-e Version-
   CiscoCatalyst 9300l-24t-4x-a Version-
   CiscoCatalyst 9300l-24t-4x-e Version-
   CiscoCatalyst 9300l-48p-4g-a Version-
   CiscoCatalyst 9300l-48p-4g-e Version-
   CiscoCatalyst 9300l-48p-4x-a Version-
   CiscoCatalyst 9300l-48p-4x-e Version-
   CiscoCatalyst 9300l-48t-4g-a Version-
   CiscoCatalyst 9300l-48t-4g-e Version-
   CiscoCatalyst 9300l-48t-4x-a Version-
   CiscoCatalyst 9300l-48t-4x-e Version-
   CiscoCatalyst 9300l Stack Version-
   CiscoCatalyst 9300lm Version-
   CiscoCatalyst 9300x Version-
   CiscoCatalyst 9500 Version-
   CiscoCatalyst 9500h Version-
   CiscoCatalyst 9600 Version-
   CiscoCatalyst 9600 Supervisor Engine-1 Version-
   CiscoCatalyst 9600x Version-
   CiscoCatalyst 9800 Version-
   CiscoCatalyst 9800-40 Version-
   CiscoCatalyst 9800-40 Wireless Controller Version-
   CiscoCatalyst 9800-80 Version-
   CiscoCatalyst 9800-80 Wireless Controller Version-
   CiscoCatalyst 9800-cl Version-
   CiscoCatalyst 9800-l Version-
   CiscoCatalyst 9800-l-c Version-
   CiscoCatalyst 9800-l-f Version-
   CiscoCatalyst 9800 Embedded Wireless Controller Version-
   CiscoCatalyst Ie3200 Rugged Switch Version-
   CiscoCatalyst Ie3300 Rugged Switch Version-

03.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability

Vulnerability

A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS could allow an unauthenticated, remote attacker to cause a denial of service.

Description

Apply updates per vendor instructions.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 14.05% 0.941
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C