EXPOSURES › CVE-2017-12240
CVE-2017-12240
HIGH ⌖ ON CISA KEV · EXPLOITEDAn unauthenticated remote attacker could execute arbitrary code and gain full control of Cisco IOS and IOS XE systems via a DHCP relay subsystem vulnerability.
This vulnerability allows remote code execution without authentication, enabling attackers to take full control of network infrastructure. DIB organizations must ensure continuous patching and strict access controls, as Cisco has a history of high-severity RCE flaws in similar subsystems. Failure to patch promptly exposes critical network devices to compromise and potential supply-chain attacks.
Shame score — A high-severity RCE in a foundational networking product that was actively exploited in the wild, reflecting systemic issues in input validation and patching cadence.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The Dynamic Host Configuration Protocol (DHCP) relay subsystem of Cisco IOS and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system.
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |