SB2017092804 - Remote DoS via PN-DCP in Cisco Industrial 2000 Ethernet Switches
Published: September 28, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper input validation (CVE-ID: CVE-2017-12235)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an error in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS Software when processing ingress PN-DCP Identify Request packets destined to an affected device. An attacker could exploit this vulnerability by sending a crafted PN-DCP Identify Request packet to an affected device and then continuing to send normal PN-DCP Identify Request packets to the device.
A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
Remediation
Install update from vendor's website.