peter bassill · operator
$ cve CVE-2017-6663 JSON

CVE-2017-6663 KEV

6.5
MEDIUM · CVSS 3.1 · EPSS 2.1% (pctl 81)

Patch first

On CISA KEV — known exploited in the wild, due 2022-03-24.

Description

A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in a denial of service (DoS) condition. More Information: CSCvd88936. Known Affected Releases: Denali-16.2.1 Denali-16.3.1.

Scoring

CVSS6.5 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS2.12% — more likely to be exploited than 81% of all CVEs
On CISA KEVyes — remediate by 2022-03-24
Public exploitnone known
Published2017-08-07
Last modified2026-06-17

CISA KEV

NameCisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability
Added2022-03-03
Due2022-03-24
Vendor / productCisco / IOS and IOS XE Software
Ransomware usenone reported

Affected (2)

VendorProduct
ciscoios
ciscoios xe

References

→ the Explorer  ·  watch your stack  ·  NVD