Cybersecurity Alerts

Actively Exploited Vulnerabilities

← Back to Cybersecurity Alerts

CVE-2017-12240

Cisco | IOS and IOS XE SoftwareAdded 2022-03-03Remediation Deadline 2022-03-24

Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability

The Dynamic Host Configuration Protocol (DHCP) relay subsystem of Cisco IOS and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system.

Required Action

Apply updates per vendor instructions.

Weakness Classification

CWE-20

References