cbcvebase.
CVE-2017-6663
published 2017-08-07

CVE-2017-6663: A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause…

PriorityP277medium6.5CVSS 3.1
AVAACLPRNUINSUCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
2.14%
80.1th percentile
A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in a denial of service (DoS) condition. More Information: CSCvd88936. Known Affected Releases: Denali-16.2.1 Denali-16.3.1.

Affected

187 ranges· showing 25
VendorProductVersion rangeFixed in
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios

Detection & IOCsextracted from sources · hover to see the quote

  • Detect exploitation attempts by monitoring for replayed packets targeting the Autonomic Control Plane (ACP) channel, which is the attack vector used to reset the ACP channel and trigger a device reload.
  • Monitor autonomic nodes for unexpected reloads, which are the observable impact of a successful exploit against the Autonomic Networking Infrastructure (ANI) ACP channel.
  • Scope detection to adjacent-segment attackers only; the vulnerability requires the attacker to be on the same network segment (adjacent) as the targeted autonomic node — remote exploitation is not possible.
  • ·Affected releases are Denali-16.2.1 and Denali-16.3.1 of Cisco IOS/IOS XE; detection and patching efforts should be scoped to these versions.
  • ·No software fix or workaround was available at time of advisory publication; mitigation relies solely on network-level controls to restrict adjacency to autonomic nodes.
  • ·The internal Cisco bug tracker ID for this vulnerability is CSCvd88936, useful for cross-referencing vendor advisories and patch notes.

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.06.1MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
vulncheck6.5MEDIUM
cisa6.5MEDIUM
vendor_cisco7.4HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.