PatchSiren cyber security CVE debrief
CVE-2017-12319 Cisco CVE debrief
Cisco IOS XE Software CVE-2017-12319 is a denial-of-service vulnerability tied to Ethernet Virtual Private Network (EVPN) Border Gateway Protocol (BGP) handling. CISA lists it in the Known Exploited Vulnerabilities catalog, so it should be treated as a known-exploited exposure and remediated according to Cisco’s instructions as soon as possible.
- Vendor
- Cisco
- Product
- IOS XE Software
- CVSS
- Unknown
- CISA KEV
- Listed
- Original CVE published
- 2022-03-03
- Original CVE updated
- 2022-03-03
- Advisory published
- 2022-03-03
- Advisory updated
- 2022-03-03
Who should care
Organizations running Cisco IOS XE Software, especially network operations and security teams responsible for devices that use EVPN/BGP features. Incident responders and patch-management teams should also prioritize it because it appears in CISA’s Known Exploited Vulnerabilities catalog.
Technical summary
The supplied records identify this issue as a Cisco IOS XE Software EVPN/BGP denial-of-service vulnerability. The corpus does not include affected version ranges, attack preconditions, or a CVSS score, but the CISA KEV entry indicates it is a known exploited vulnerability. The practical defensive takeaway is to inventory Cisco IOS XE systems, confirm whether EVPN/BGP functionality is in use, and apply vendor-provided updates promptly.
Defensive priority
High — CISA KEV-listed; prioritize remediation immediately and track against the supplied 2022-03-24 due date if the asset is still exposed.
Recommended defensive actions
- Apply Cisco updates per vendor instructions.
- Inventory Cisco IOS XE Software devices and identify systems using EVPN/BGP functionality.
- Prioritize remediation for critical, internet-facing, or hard-to-maintain network infrastructure.
- Coordinate maintenance windows to update affected devices without delaying remediation unnecessarily.
- Review network and device logs for unusual service disruption consistent with a denial-of-service condition.
Evidence notes
The debrief is based only on the supplied CVE metadata, the CISA KEV source item, and the official reference links. The corpus provides the vulnerability title, KEV inclusion date (2022-03-03), due date (2022-03-24), and the required action to apply updates per vendor instructions. No CVSS score, affected-version range, or vendor advisory text was supplied.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-12319 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-12319
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-12319 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-12319
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.