CVE-2017-6663 KEV
6.5
MEDIUM · CVSS 3.1 · EPSS 2.1% (pctl 81)
Patch first
On CISA KEV — known exploited in the wild, due 2022-03-24.
Description
A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in a denial of service (DoS) condition. More Information: CSCvd88936. Known Affected Releases: Denali-16.2.1 Denali-16.3.1.
Scoring
| CVSS | 6.5 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| EPSS | 2.12% — more likely to be exploited than 81% of all CVEs |
| On CISA KEV | yes — remediate by 2022-03-24 |
| Public exploit | none known |
| Published | 2017-08-07 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability |
|---|---|
| Added | 2022-03-03 |
| Due | 2022-03-24 |
| Vendor / product | Cisco / IOS and IOS XE Software |
| Ransomware use | none reported |
Affected (2)
| Vendor | Product |
|---|---|
| cisco | ios |
| cisco | ios xe |
References
- http://www.securityfocus.com/bid/99973
- http://www.securitytracker.com/id/1038999
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170726-anidos
- http://www.securityfocus.com/bid/99973
- http://www.securitytracker.com/id/1038999
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170726-anidos
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6663
→ the Explorer · watch your stack · NVD