CVE-2012-4617: Cisco IOS
High severity, CVSS 7.1. EPSS: 2.3% chance of exploitation in the next 30 days.
The BGP implementation in Cisco IOS 15.2, IOS XE 3.5.xS before 3.5.2S, and IOS XR 4.1.0 through 4.2.2 allows remote attackers to cause a denial of service (multiple connection resets) by leveraging a peer relationship and sending a malformed attribute, aka Bug IDs CSCtt35379, CSCty58300, CSCtz63248, and CSCtz62914.
Affected products
- Cisco IOS: version 15.2 only
- Cisco IOS XE: version 3.5.0s only; version 3.5.1s only
- Cisco IOS XR: version 4.1 only; version 4.1.1 only; version 4.1.2 only; version 4.2.0 only; version 4.2.1 only; version 4.2.2 only
Published 2012-09-27. Last modified 2026-06-16.