CVE-2017-12231 describes a denial-of-service vulnerability in Cisco IOS 12.4 through 15.6, specifically impacting devices configured with NAT Application Layer Gateway (ALG) for H.323 RAS messages. An unauthenticated, remote attacker can exploit this by sending a crafted H.323 RAS packet through an affected device, causing it to crash and reload. This vulnerability has a CVSS score of 7.5 (High) due to its network-based attack vector, low complexity, and high impact on availability. Notably, this CVE is listed in CISA's KEV catalog, indicating active exploitation in the wild, despite a lack of public exploit code on platforms like Metasploit or ExploitDB. The vulnerability has garnered significant community discussion, with 10 mentions, but no media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.4, <= 15.6CPE matchmatch criteria | cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.