ZeroHour

CVE-2017-6663

KEVlarge

Unauthenticated Adjacent-DoS in Cisco IOS and IOS XE Autonomic Networking

CISA: Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability

CVSS 3.1
6.5 medium
EPSS
2%p81
Published
()
KEV added
AI analysis

CVE-2017-6663 is a denial-of-service flaw in the Autonomic Networking feature of Cisco IOS and Cisco IOS XE Software. An unauthenticated attacker positioned on an adjacent network segment (CVSS vector AV:A, i.e., Layer-2/adjacent reachability) can send crafted traffic that causes autonomic nodes of the affected device to reload repeatedly. The attacker gains availability impact only — forced device reloads and network disruption — with no confidentiality or confidentiality impact (CIA vector: C:N/I:N/A:H), rated 6.5 Medium. Affected users are operators running the known affected releases, Denali-16.2.1 and Denali-16.3.1, of IOS or IOS XE. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03, indicating exploitation has been observed in the wild (ransomware use: unknown); EPSS estimates a 2.1% chance of exploitation in the next 30 days (81st percentile), and no public proof-of-concept is known.

What to do: Apply updates per vendor instructions (per the CISA KEV required action): upgrade devices off the known affected Denali-16.2.1 and Denali-16.3.1 releases to a fixed IOS/IOS XE release per Cisco's advisory. As an interim mitigation, restrict untrusted hosts from Layer-2 adjacency to devices with Autonomic Networking enabled and monitor for unexpected device reloads. Inventory IOS/IOS XE devices running 16.2.1 or 16.3.1 and prioritize any that are KEV-driven or in critical network paths.

Affected
Cisco IOSKnown affected releases: Denali-16.2.1, Denali-16.3.1 (Autonomic Networking feature)
Cisco IOS XEKnown affected releases: Denali-16.2.1, Denali-16.3.1 (Autonomic Networking feature)
Estimated exposure
largeon the order of hundreds of thousands of IOS/IOS XE devices potentially affected (estimate) — Cisco's IOS/IOS XE installed base spans millions of enterprise routing and switching devices and the Denali 16.2/16.3 trains were mainstream releases, so a residual device population on the order of 10^5 is plausible, though the adjacent…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in a denial of service (DoS) condition. More Information: CSCvd88936. Known Affected Releases: Denali-16.2.1 Denali-16.3.1.

CISA Known Exploited Vulnerability
Affected
Cisco IOS and IOS XE Software
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
ios, ios xe
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.