LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-6627: Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-6627 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A vulnerability in the UDP processing code of Cisco IOS and IOS XE could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an…

CVE-2017-6627 is a denial-of-service vulnerability in the UDP packet processing code of Cisco IOS and IOS XE Software. An unauthenticated remote attacker can cause an affected device to hold UDP packets in an interface input queue, creating a queue wedge that disrupts normal traffic handling and can take the interface or device out of service. For network teams this matters because IOS and IOS XE commonly run on routers, switches, and other infrastructure that sit in the path of critical traffic; a successful attack can interrupt connectivity without any credentials.

Public detail is limited to the vendor and CISA descriptions. Confirm exact affected releases, fixed versions, and any platform-specific notes directly against the Cisco advisory before acting.

How it works

The weakness is classified as CWE-399 (resource management errors). In this case the flaw lies in how the software handles certain UDP packets. When those packets are processed, the device can fail to release or properly drain them from the interface input queue. Over time the queue fills and becomes wedged, so legitimate traffic that should be forwarded or delivered is blocked. The attacker needs only network reachability to the vulnerable UDP processing path; no authentication is required. The result is a denial-of-service condition rather than code execution or data theft. Exact packet characteristics and trigger conditions are not provided in the summary material and must be taken from the vendor advisory if needed for detection engineering.

Am I affected? How to find it in your systems

Cisco IOS and IOS XE are typically found on enterprise and service-provider routers, Layer-3 switches, and certain security or aggregation appliances. Inventory every device running either operating system:

Telemetry signs of exploitation or the resulting condition include sudden growth in input-queue counters, interfaces reporting queue wedges, unexplained drops or loss of forwarding on UDP-bearing interfaces, and device or interface-level denial-of-service symptoms without a corresponding hardware failure. Capture show interface, show buffers, and related queue statistics before and during any suspected event, and retain logs for later correlation. Because public exploit details are sparse, treat any unexplained UDP-related queue exhaustion on an unpatched device as suspicious until proven otherwise.

How to remediate

Patch first. Apply the software updates Cisco released for this vulnerability, following the exact image and upgrade path named in the vendor advisory. CISA’s required action is to apply updates per vendor instructions; schedule the upgrade in a maintenance window that includes verification of interface and routing health afterward.

After patching, perform basic hardening appropriate to this class of flaw:

Re-inventory after the change window to confirm every previously vulnerable device now runs a fixed release.

If you can't patch immediately

Until the vendor update can be installed, reduce risk with compensating controls:

These steps only buy time; they do not replace the software fix.

If your data may have been exposed

This vulnerability is a denial-of-service issue; the public record does not document direct data exfiltration or ransomware use tied to CVE-2017-6627. Nonetheless, any successful attack on network infrastructure can be a precursor to broader compromise. If you have evidence that devices were wedged or that an attacker maintained presence afterward, follow your incident-response process, preserve logs, and check for secondary access. You can also run a free exposure scan of your email addresses against known breach data sets to see whether credentials or other information have appeared in unrelated breaches while you complete containment and patching.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · IOS and IOS XE Software
WeaknessCWE-399
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 24, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities