CVE-2017-12238
A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a denial of service (DoS) condition. The vulnerability is due to a memory management issue in the affected software. An attacker could exploit this vulnerability by creating a large number of VPLS-generated MAC entries in the MAC address table of an affected device. A successful exploit could allow the attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a DoS condition. This vulnerability affects Cisco Catalyst 6800 Series Switches that are running a vulnerable release of Cisco IOS Software and have a Cisco C6800-16P10G or C6800-16P10G-XL line card in use with Supervisor Engine 6T. To be vulnerable, the device must also be configured with VPLS and the C6800-16P10G or C6800-16P10G-XL line card needs to be the core-facing MPLS interfaces. Cisco Bug IDs: CSCva61927.
Weaknesses (CWE)
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| cisco | ios | all |
| cisco | c6800-16p10g | all |
| cisco | c6800-16p10g-xl | all |
| cisco | catalyst_6000 | all |
| cisco | catalyst_6000_ws-svc-nam-1 | 2.2\(1a\), 3.1\(1a\) |
| cisco | catalyst_6000_ws-svc-nam-2 | 2.2\(1a\), 3.1\(1a\) |
| cisco | catalyst_6000_ws-x6380-nam | 2.1\(2\), 3.1\(1a\) |
| cisco | catalyst_6500 | all |
| cisco | catalyst_6500-e | all |
| cisco | catalyst_6500_ws-svc-nam-1 | 2.2\(1a\), 3.1\(1a\) |
| cisco | catalyst_6500_ws-svc-nam-2 | 2.2\(1a\), 3.1\(1a\) |
| cisco | catalyst_6500_ws-x6380-nam | 2.1\(2\), 3.1\(1a\) |
| cisco | catalyst_6503-e | all |
| cisco | catalyst_6504-e | all |
| cisco | catalyst_6506-e | all |
| cisco | catalyst_6509-e | all |
| cisco | catalyst_6509-neb-a | all |
| cisco | catalyst_6509-v-e | all |
| cisco | catalyst_6513 | all |
| cisco | catalyst_6513-e | all |
References & Technical Advisories
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Cisco Systems, Inc. · Hosted Service · USA |
| Reserved | 2017-08-03T00:00:00 |
| Published | 2017-09-28T07:00:00 |
| Patch Date | 2017-09-28 |
| Last Updated | 2026-01-12T21:46:19 |
Community Chatter & Buzz