CVE-2017-6663
published 2017-08-07CVE-2017-6663: A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause…
PriorityP277medium6.5CVSS 3.1
AVAACLPRNUINSUCNINAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
2.14%
80.1th percentile
A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in a denial of service (DoS) condition. More Information: CSCvd88936. Known Affected Releases: Denali-16.2.1 Denali-16.3.1.
Affected
187 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation attempts by monitoring for replayed packets targeting the Autonomic Control Plane (ACP) channel, which is the attack vector used to reset the ACP channel and trigger a device reload. ↗
- →Monitor autonomic nodes for unexpected reloads, which are the observable impact of a successful exploit against the Autonomic Networking Infrastructure (ANI) ACP channel. ↗
- →Scope detection to adjacent-segment attackers only; the vulnerability requires the attacker to be on the same network segment (adjacent) as the targeted autonomic node — remote exploitation is not possible. ↗
- ·Affected releases are Denali-16.2.1 and Denali-16.3.1 of Cisco IOS/IOS XE; detection and patching efforts should be scoped to these versions. ↗
- ·No software fix or workaround was available at time of advisory publication; mitigation relies solely on network-level controls to restrict adjacency to autonomic nodes. ↗
- ·The internal Cisco bug tracker ID for this vulnerability is CSCvd88936, useful for cross-referencing vendor advisories and patch notes. ↗
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.06.1MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
vulncheck6.5MEDIUM
cisa6.5MEDIUM
vendor_cisco7.4HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability
cisa·2022-03-03·CVSS 6.5
CVE-2017-6663 [MEDIUM] Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability
Vulnerability: Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability
Affected: Cisco IOS and IOS XE Software
A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in denial-of-service (DoS).
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-6663
Remediation Due Date: 2022-03-24
Cisco
Cisco IOS and IOS XE Software Autonomic Networking Infrastructure Denial of Service Vulnerability
vendor_cisco·2017-07-26·CVSS 7.4
CVE-2017-6663 [HIGH] Cisco IOS and IOS XE Software Autonomic Networking Infrastructure Denial of Service Vulnerability
Cisco IOS and IOS XE Software Autonomic Networking Infrastructure Denial of Service Vulnerability
A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in a denial of service (DoS) condition.
The vulnerability is due to an unknown condition in the Autonomic Networking code of the affected software. An attacker could exploit this vulnerability by replaying captured packets to reset the Autonomic Control Plane (ACP) channel of an affected system. A successful exploit could allow the attacker to reset the ACP channel of an affected system and consequently cause the affected device to reload, resulting in a DoS condition.
Cisco h
Cisco
Cisco IOS and IOS XE Software Autonomic Networking Infrastructure Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-6663 Cisco IOS and IOS XE Software Autonomic Networking Infrastructure Denial of Service Vulnerability
CVE-2017-6663: Cisco IOS and IOS XE Software Autonomic Networking Infrastructure Denial of Service Vulnerability
A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to an unknown condition in the Autonomic Networking code of the affected software. An attacker could exploit this vulnerability by replaying captured packets to reset the Autonomic Control Plane (ACP) channel of an affected system. A successful exploit could allow the attacker to reset the ACP channel of an affected system and consequently cause the affected device to reload, resulting in a DoS condit
GHSA
GHSA-3h3r-w377-6ffg: A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker
ghsa_unreviewed·2022-05-13
CVE-2017-6663 [MEDIUM] GHSA-3h3r-w377-6ffg: A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker
A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in a denial of service (DoS) condition. More Information: CSCvd88936. Known Affected Releases: Denali-16.2.1 Denali-16.3.1.
VulnCheck
Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability
vulncheck·2017·CVSS 6.5
CVE-2017-6663 [MEDIUM] Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability
Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability
A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in denial-of-service (DoS).
Affected: Cisco IOS and IOS XE Software
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-03-24
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/99973http://www.securitytracker.com/id/1038999https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170726-anidoshttp://www.securityfocus.com/bid/99973http://www.securitytracker.com/id/1038999https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170726-anidoshttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6663
2017-08-07
Published
2022-03-03
Added to CISA KEV
Exploited in the wild