PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-12319 Cisco CVE debrief

Cisco IOS XE Software CVE-2017-12319 is a denial-of-service vulnerability tied to Ethernet Virtual Private Network (EVPN) Border Gateway Protocol (BGP) handling. CISA lists it in the Known Exploited Vulnerabilities catalog, so it should be treated as a known-exploited exposure and remediated according to Cisco’s instructions as soon as possible.

Vendor
Cisco
Product
IOS XE Software
CVSS
Unknown
CISA KEV
Listed
Original CVE published
2022-03-03
Original CVE updated
2022-03-03
Advisory published
2022-03-03
Advisory updated
2022-03-03

Who should care

Organizations running Cisco IOS XE Software, especially network operations and security teams responsible for devices that use EVPN/BGP features. Incident responders and patch-management teams should also prioritize it because it appears in CISA’s Known Exploited Vulnerabilities catalog.

Technical summary

The supplied records identify this issue as a Cisco IOS XE Software EVPN/BGP denial-of-service vulnerability. The corpus does not include affected version ranges, attack preconditions, or a CVSS score, but the CISA KEV entry indicates it is a known exploited vulnerability. The practical defensive takeaway is to inventory Cisco IOS XE systems, confirm whether EVPN/BGP functionality is in use, and apply vendor-provided updates promptly.

Defensive priority

High — CISA KEV-listed; prioritize remediation immediately and track against the supplied 2022-03-24 due date if the asset is still exposed.

Recommended defensive actions

  • Apply Cisco updates per vendor instructions.
  • Inventory Cisco IOS XE Software devices and identify systems using EVPN/BGP functionality.
  • Prioritize remediation for critical, internet-facing, or hard-to-maintain network infrastructure.
  • Coordinate maintenance windows to update affected devices without delaying remediation unnecessarily.
  • Review network and device logs for unusual service disruption consistent with a denial-of-service condition.

Evidence notes

The debrief is based only on the supplied CVE metadata, the CISA KEV source item, and the official reference links. The corpus provides the vulnerability title, KEV inclusion date (2022-03-03), due date (2022-03-24), and the required action to apply updates per vendor instructions. No CVSS score, affected-version range, or vendor advisory text was supplied.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-12319 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-12319

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-12319 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-12319

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.