LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-6663: Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-6663 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to…

CVE-2017-6663 is a denial-of-service vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software. An unauthenticated attacker on an adjacent network segment can cause affected autonomic nodes to reload, disrupting availability of those devices.

For IT and security teams running Cisco routing and switching infrastructure that may have Autonomic Networking enabled, this matters because a successful attack can take nodes offline without credentials. Confirm exact product coverage and fixed releases against the vendor advisory before acting.

How it works

The flaw resides in the Autonomic Networking feature of Cisco IOS and IOS XE. According to the CISA summary, an unauthenticated, adjacent attacker can trigger a condition that forces autonomic nodes on an affected system to reload, producing a denial-of-service condition.

Public detail on the precise weakness class (CWE) and low-level exploit mechanics is limited. In general terms for this product class, the attacker must be able to reach the Autonomic Networking control plane from an adjacent segment; no authentication is required. Specifics of packet content or protocol abuse must be confirmed against the Cisco advisory rather than assumed.

Am I affected? How to find it in your systems

Cisco IOS and IOS XE commonly run on enterprise and service-provider routers, switches, and related network devices. Inventory every device that could have Autonomic Networking configured or enabled.

How to remediate

Patch first. Apply the Cisco software updates identified in the vendor advisory for CVE-2017-6663, following Cisco’s published instructions. CISA’s required action is to apply updates per vendor instructions.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls appropriate to an adjacent, unauthenticated DoS against Autonomic Networking.

If your data may have been exposed

This vulnerability is described as a denial-of-service condition that causes reloads; the provided facts do not document data exfiltration or ransomware use. Actively exploited vulnerabilities can still lead to broader incidents if attackers use disruption as cover for other activity, so verify device integrity and review adjacent logs after any suspicious reload. You can run a free exposure scan of your email addresses against known breach data to check whether credentials or other records associated with your organization have appeared in unrelated breaches.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · IOS and IOS XE Software
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 24, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities