CVE-2017-6663: Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability
A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in a denial of service (DoS) condition. More Information: CSCvd88936. Known Affected Releases: Denali-16.2.1 Denali-16.3.1.
Other sources
A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in denial-of-service (DoS).
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cisco IOSto a version that resolves this vulnerability.Patch CSCvd88936 - Upgrade
Upgrade
Cisco IOS XEto a version that resolves this vulnerability.Patch CSCvd88936
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6663?
CVE-2017-6663 is rated as a high severity vulnerability due to its potential to lead to a denial of service.
How do I fix CVE-2017-6663?
To fix CVE-2017-6663, it is recommended to apply the latest firmware updates from Cisco for affected IOS and IOS XE versions.
Who is affected by CVE-2017-6663?
CVE-2017-6663 affects several versions of Cisco IOS and IOS XE Software supporting the Autonomic Networking feature.
What impact does CVE-2017-6663 have?
CVE-2017-6663 can allow an unauthenticated adjacent attacker to cause a denial of service condition by reloading autonomic nodes.
When was CVE-2017-6663 discovered?
CVE-2017-6663 was disclosed on July 26, 2017.