CVE-2017-6663
Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 March 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in a denial of service (DoS) condition. More Information: CSCvd88936. Known Affected Releases: Denali-16.2.1 Denali-16.3.1.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.14% probability · 81th percentile
- CISA KEV
- Listed 3 March 2022 · due 24 March 2022
- Affected
- cisco/ios · cisco/ios xe
- Source
- psirt@cisco.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2017-6663
References
- http://www.securityfocus.com/bid/99973Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038999Broken Link, Third Party Advisory, VDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170726-anidosVendor Advisory
- http://www.securityfocus.com/bid/99973Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038999Broken Link, Third Party Advisory, VDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170726-anidosVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6663US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.