CVE-2017-6663

MEDIUM(6.5)KEV

Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability

Description

CVE-2017-6663 is a denial-of-service vulnerability in Cisco IOS and IOS XE Software. A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in denial-of-service (DoS). Successful exploitation could result in denial of service through device reloads on affected devices. CISA has added CVE-2017-6663 to the Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The EPSS score of 2.32% (84.6th percentile) indicates a measurable likelihood of exploitation activity.

KEV Information

Vendor
Cisco
Product
IOS and IOS XE Software
Date Added
March 3, 2022
Due Date
March 24, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HOpen in Calculator
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
3.6

Affected Products

VendorProductVersion
ciscoios15.2\(3\)e; 15.2\(3\)e1; 15.2\(3\)e2; 15.2\(3\)e3; 15.2\(3\)e4; 15.2\(3\)e5; 15.2\(3a\)e; 15.2\(3a\)e1; 15.2\(3m\)e2; 15.2\(3m\)e3; 15.2\(3m\)e6; 15.2\(3m\)e8; 15.2\(4\)e; 15.2\(4\)e1; 15.2\(4\)e2; 15.2\(4\)e3; 15.2\(5\)e; 15.2\(5\)e1; 15.2\(5a\)e; 15.2\(5b\)e; 15.3\(3\)s; 15.3\(3\)s1; 15.3\(3\)s1a; 15.3\(3\)s2; 15.3\(3\)s3; 15.3\(3\)s4; 15.3\(3\)s5; 15.3\(3\)s6; 15.3\(3\)s7; 15.3\(3\)s8; 15.3\(3\)s8a; 15.3\(3\)s9; 15.3\(3\)s10; 15.4\(1\)s; 15.4\(1\)s1; 15.4\(1\)s2; 15.4\(1\)s3; 15.4\(1\)s4; 15.4\(2\)s; 15.4\(2\)s1; 15.4\(2\)s2; 15.4\(2\)s3; 15.4\(2\)s4; 15.4\(3\)s; 15.4\(3\)s1; 15.4\(3\)s2; 15.4\(3\)s3; 15.4\(3\)s4; 15.4\(3\)s5; 15.4\(3\)s5a; 15.4\(3\)s6; 15.4\(3\)s6a; 15.4\(3\)s6b; 15.4\(3\)s7; 15.4\(3\)s7a; 15.4\(3\)s8; 15.5\(1\)s; 15.5\(1\)s1; 15.5\(1\)s2; 15.5\(1\)s3; 15.5\(1\)s4; 15.5\(2\)s; 15.5\(2\)s1; 15.5\(2\)s2; 15.5\(2\)s3; 15.5\(2\)s4; 15.5\(3\)s; 15.5\(3\)s0a; 15.5\(3\)s1; 15.5\(3\)s1a; 15.5\(3\)s2; 15.5\(3\)s2a; 15.5\(3\)s2b; 15.5\(3\)s3; 15.5\(3\)s3a; 15.5\(3\)s4; 15.5\(3\)s4a; 15.5\(3\)s4b; 15.5\(3\)s4d; 15.5\(3\)s5; 15.5\(3\)sn; 15.6\(1\)s; 15.6\(1\)s1; 15.6\(1\)s1a; 15.6\(1\)s2; 15.6\(1\)s3; 15.6\(1\)s4; 15.6\(1\)t; 15.6\(1\)t0a; 15.6\(1\)t1; 15.6\(1\)t2; 15.6\(2\)s; 15.6\(2\)s0a; 15.6\(2\)s1; 15.6\(2\)s2; 15.6\(2\)s3; 15.6\(2\)s4; 15.6\(2\)sn; 15.6\(2\)sp; 15.6\(2\)sp1; 15.6\(2\)sp1b; 15.6\(2\)sp1c; 15.6\(2\)sp2; 15.6\(2\)sp2a; 15.6\(2\)sp3; 15.6\(2\)t; 15.6\(2\)t1; 15.6\(2\)t2; 15.6\(2\)t3; 15.6\(3\)m; 15.6\(3\)m0a; 15.6\(3\)m1; 15.6\(3\)m1b; 15.6\(3\)m2; 15.6\(3\)m2a; 15.6\(3\)m3; 15.7\(3\)m
ciscoios xe3.7.0e; 3.7.1e; 3.7.3e; 3.8.0e; 3.8.0ex; 3.8.1e; 3.8.2e; 3.8.3e; 3.9.0e; 3.9.1e; 3.10.4s; 3.10.8as; 3.10.8s; 3.11.3s; 3.11.4s; 3.12.0as; 3.12.0s; 3.12.1s; 3.12.2s; 3.12.3s; 3.12.4s; 3.13.0s; 3.13.1s; 3.13.2as; 3.13.2s; 3.13.4s; 3.13.5as; 3.13.5s; 3.13.6as; 3.13.6s; 3.13.7as; 3.13.8s; 3.14.0s; 3.14.1s; 3.14.2s; 3.14.3s; 3.14.4s; 3.15.0s; 3.15.1s; 3.15.2s; 3.15.3s; 3.15.4s; 3.16.0s; 3.16.1as; 3.16.2as; 3.16.2s; 3.16.3as; 3.16.3s; 3.16.4as; 3.16.4ds; 3.16.4s; 3.16.6s; 3.17.0s; 3.17.1as; 3.17.1s; 3.17.3s; 3.17.4s; 3.18.0as; 3.18.0s; 3.18.0sp; 3.18.1bsp; 3.18.1s; 3.18.1sp; 3.18.2asp; 3.18.2s; 3.18.2sp; 3.18.3s; 3.18.3sp; 16.6.1

Multiple CVSS Assessments

Source: [email protected](Primary)
6.5
MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
6.5
MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

Weakness Type

Weakness Not Classified

No specific CWE has been assigned to CVE-2017-6663. The vulnerability relates to denial-of-service vulnerability behavior in Cisco IOS and IOS XE Software that can be triggered by an adjacent network attacker.

Learn more: CWE Overview

Impact Analysis

CVE-2017-6663 threatens the availability of Cisco IOS and IOS XE Software, as exploitation can cause device reloads, resulting in service disruption. With a CVSS score of 6.5 (MEDIUM) and an adjacent network attack vector requiring no authentication, the barrier to exploitation is low. In enterprise environments, repeated exploitation could cause sustained network outages affecting business operations, communications, and service availability. Network infrastructure devices are high-value targets, and their unavailability can have cascading effects across the organization.

Exploit Maturity

CVE-2017-6663 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming that this vulnerability has been exploited in real-world attacks. The EPSS score of 2.32% (84.6th percentile) indicates a measurable probability of exploitation. Organizations should treat this vulnerability as an active and ongoing threat requiring immediate remediation.

Remediation

  1. Apply vendor updates immediately as required by CISA KEV: Apply updates per vendor instructions.
  2. If immediate patching is not possible, implement interim mitigations such as restricting access to the affected Autonomic Networking feature to trusted networks only using access control lists.
  3. Monitor affected devices for signs of exploitation, including unexpected reloads, unusual network traffic, and anomalous process behavior.
  4. Ensure network monitoring and alerting is configured to detect denial-of-service conditions affecting the Cisco IOS and IOS XE Software infrastructure.
  5. Maintain up-to-date device configurations and backups to enable rapid recovery if exploitation causes device reloads.

Technical Details

CVE-2017-6663 is a denial-of-service vulnerability in the Autonomic Networking feature of Cisco IOS and IOS XE Software. The vulnerability allows an unauthenticated adjacent attacker to cause the device to reload by sending specially crafted packets. The CVSS v3.1 score of 6.5 reflects low attack complexity, no required privileges, and high impact on availability. The attack vector is adjacent network, meaning an attacker must have access to the same network segment as the target.

Frequently Asked Questions

Is CVE-2017-6663 being actively exploited?

Yes. CVE-2017-6663 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation. The EPSS score of 2.32% (84.6th percentile) further indicates a notable likelihood of ongoing exploitation.

What products are affected by CVE-2017-6663?

CVE-2017-6663 affects Cisco IOS and IOS XE Software. Specifically, affected products include Cisco Ios, Cisco Ios Xe.

How do I fix CVE-2017-6663?

Apply updates per vendor instructions. If immediate patching is not feasible, apply interim mitigations such as access control restrictions and enhanced monitoring to detect exploitation attempts.

How severe is CVE-2017-6663?

CVE-2017-6663 has a CVSS score of 6.5 (MEDIUM). This is a medium-severity denial-of-service vulnerability that can disrupt network operations. While it does not enable code execution, the availability impact on critical network infrastructure makes timely remediation essential.

CVSS Score

6.5
MEDIUM(6.5)

EPSS Score

EPSS Score2.14%
EPSS Percentile80.5%

Dates

PublishedAugust 7, 2017
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.