CVE-2017-12240 is a critical buffer overflow vulnerability in the DHCP relay subsystem of Cisco IOS (versions 12.2-15.6) and Cisco IOS XE Software. This flaw allows an unauthenticated, remote attacker to execute arbitrary code, gaining full control of the affected system, or trigger a denial of service by causing a reload. With a CVSS score of 9.8 (CRITICAL), it is easily exploitable over the network with low attack complexity, posing a significant risk to confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, as indicated by its presence in the KEV catalog, and has garnered substantial community discussion and media coverage, despite no public exploit code being readily available through common frameworks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.2, <= 15.6CPE matchmatch criteria | cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.