← KEV catalog
CISA known exploited vulnerability

CVE-2017-12240

Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability

SOURCE FACT

Cisco · IOS and IOS XE Software

The Dynamic Host Configuration Protocol (DHCP) relay subsystem of Cisco IOS and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2017-12240

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?