First published: Tue Jun 13 2017(Updated: )
A vulnerability in the forwarding component of Cisco IOS XR Software for Cisco Network Convergence System (NCS) 5500 Series Routers could allow an authenticated, local attacker to cause the router to stop forwarding data traffic across Traffic Engineering (TE) tunnels, resulting in a denial of service (DoS) condition. More Information: CSCvd16665. Known Affected Releases: 6.2.11.BASE. Known Fixed Releases: 6.1.3 6.1.2 6.3.1.8i.BASE 6.2.11.8i.BASE 6.2.2.9i.BASE 6.1.32.11i.BASE 6.1.31.10i.BASE 6.1.4.3i.BASE.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XRv 9000 | =6.0.0 | |
Cisco IOS XRv 9000 | =6.0.1 | |
Cisco IOS XRv 9000 | =6.0_base | |
Cisco IOS XRv 9000 | =6.1.0 | |
Cisco IOS XRv 9000 | =6.1.1 | |
Cisco IOS XRv 9000 | =6.1.2 | |
Cisco IOS XRv 9000 | =6.1.3 | |
Cisco IOS XRv 9000 | =6.2.0 | |
Cisco IOS XRv 9000 | =6.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6666 has been rated as critical due to its potential to cause denial of service on affected Cisco routers.
To mitigate CVE-2017-6666, upgrade the affected Cisco IOS XR Software to a version that contains the relevant security fixes.
CVE-2017-6666 affects various versions of Cisco IOS XR Software on Cisco Network Convergence System (NCS) 5500 Series Routers.
CVE-2017-6666 requires local authentication, meaning it cannot be exploited remotely by unauthenticated attackers.
Exploitation of CVE-2017-6666 can disrupt data traffic across Traffic Engineering tunnels, leading to significant downtime.