CISA Known Exploited Vulnerability

CVE-2017-12240

Cisco · IOS and IOS XE Software

Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability

Date added
BOD 22-01 due date
CWE CWE-20
Ransomware Unknown

CISA description

The Dynamic Host Configuration Protocol (DHCP) relay subsystem of Cisco IOS and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system.

Required action

Apply updates per vendor instructions.