CVE-2017-12319 is a critical vulnerability in Cisco IOS XE Software, specifically affecting devices configured for BGP EVPN. An unauthenticated, remote attacker can exploit a flaw in how crafted BGP packets are processed, leading to device reloads or BGP routing table corruption, resulting in a denial of service. With a CVSS score of 5.9 (Medium) and a FAUCET Risk Score of 98/100, this vulnerability is considered severe due to its network-wide impact and low attack complexity. Notably, this CVE is listed in CISA's KEV catalog, indicating active exploitation, despite no public exploit code or Metasploit/Nuclei modules being available. Community discussion is high, suggesting significant awareness and concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.4\(1\)sCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.4\(1\)s:*:*:*:*:*:*:* | ||
< 16.3CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.