CVE-2017-6663
KEVlargeUnauthenticated Adjacent-DoS in Cisco IOS and IOS XE Autonomic Networking
CISA: Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability
CVE-2017-6663 is a denial-of-service flaw in the Autonomic Networking feature of Cisco IOS and Cisco IOS XE Software. An unauthenticated attacker positioned on an adjacent network segment (CVSS vector AV:A, i.e., Layer-2/adjacent reachability) can send crafted traffic that causes autonomic nodes of the affected device to reload repeatedly. The attacker gains availability impact only — forced device reloads and network disruption — with no confidentiality or confidentiality impact (CIA vector: C:N/I:N/A:H), rated 6.5 Medium. Affected users are operators running the known affected releases, Denali-16.2.1 and Denali-16.3.1, of IOS or IOS XE. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03, indicating exploitation has been observed in the wild (ransomware use: unknown); EPSS estimates a 2.1% chance of exploitation in the next 30 days (81st percentile), and no public proof-of-concept is known.
What to do: Apply updates per vendor instructions (per the CISA KEV required action): upgrade devices off the known affected Denali-16.2.1 and Denali-16.3.1 releases to a fixed IOS/IOS XE release per Cisco's advisory. As an interim mitigation, restrict untrusted hosts from Layer-2 adjacency to devices with Autonomic Networking enabled and monitor for unexpected device reloads. Inventory IOS/IOS XE devices running 16.2.1 or 16.3.1 and prioritize any that are KEV-driven or in critical network paths.
| Cisco IOS | Known affected releases: Denali-16.2.1, Denali-16.3.1 (Autonomic Networking feature) |
| Cisco IOS XE | Known affected releases: Denali-16.2.1, Denali-16.3.1 (Autonomic Networking feature) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in a denial of service (DoS) condition. More Information: CSCvd88936. Known Affected Releases: Denali-16.2.1 Denali-16.3.1.
- Affected
- Cisco IOS and IOS XE Software
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- ios, ios xe
- Vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.