← Vulnerability feed

Vulnerability record · CVE-2017-6663 · published 7 August 2017

CVE-2017-6663: Cisco IOS/IOS XE Autonomic Networking DoS via node reload

Cisco · Ios

A flaw in the Autonomic Networking feature of Cisco IOS and IOS XE lets an unauthenticated, adjacent attacker force autonomic nodes to reload, producing a denial-of-service condition. The record names only Denali-16.2.1 and Denali-16.3.1 as known affected releases, and the CWE entry carries no specific weakness class. It matters because a single adjacent attacker can repeatedly disrupt routing and network availability without credentials.

6.5 CVSS 3.1 Medium CISA KEV since 3 Mar 2022 EPSS 2.1% · top 18.9%
6.5CVSS 3.1 base score, v2 6.1
2.1%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in a denial of service (DoS) condition. More Information: CSCvd88936. Known Affected Releases: Denali-16.2.1 Denali-16.3.1.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is unauthenticated and adjacent-reachable with high availability impact, and it is in CISA KEV, though the CVSS score is only 6.5 and EPSS is low.

What it is

A flaw in the Autonomic Networking feature of Cisco IOS and IOS XE lets an unauthenticated, adjacent attacker force autonomic nodes to reload, producing a denial-of-service condition. The record names only Denali-16.2.1 and Denali-16.3.1 as known affected releases, and the CWE entry carries no specific weakness class. It matters because a single adjacent attacker can repeatedly disrupt routing and network availability without credentials.

Impact

The attacker can cause affected autonomic nodes to reload, taking them out of service and disrupting network availability for as long as the attack is repeated. No confidentiality or integrity impact is described; the effect is availability only.

Attack surface

Reached from an adjacent network position (AV:A) with no authentication (PR:N) and no user interaction (UI:N), per the CVSS vector. The description does not state which protocol or packet triggers the reload, so the exact adjacent vector is not detailed in this record.

Exploitation

CVE-2017-6663 is listed in CISA KEV (added 2022-03-03, due 2022-03-24), indicating known exploitation, while EPSS is low at roughly 2.1 percent (81st percentile). No ransomware campaign use is recorded, and the reference tags are vendor advisory, VDB entries and a US government resource.

What to do

  • Apply the Cisco IOS/IOS XE updates referenced in the vendor advisory cisco-sa-20170726-anidos, prioritizing Denali-16.2.1 and Denali-16.3.1 systems.
  • If Autonomic Networking is not required, disable it on affected devices to remove the exposed feature.
  • Restrict and monitor adjacent-layer access to autonomic-capable network segments so untrusted hosts cannot reach them.
  • Track KEV remediation deadlines for any remaining unpatched devices and schedule upgrades accordingly.

Detection

  • Alert on unexpected reload or restart events on Cisco IOS/IOS XE devices running Autonomic Networking, correlated with adjacency changes.
  • Monitor for repeated, unexplained node reloads across autonomic domains that could indicate a sustained DoS attempt.
  • Review logs for anomalous traffic from adjacent hosts toward autonomic-capable interfaces, since the record does not specify the triggering packet.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-6663 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-6663 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2023-20198Cisco IOS XE Web UI unauthenticated privilege escalation and implant deploymentCVE-2023-20198 is a critical flaw in the Cisco IOS XE web UI that lets an unauthenticated remote attacker gain initial access and create a local priv…KEVEPSS 100%analysed9.8CVE-2018-0171Cisco IOS Smart Install improper input validation allows remote code executionCisco IOS and IOS XE Smart Install fails to properly validate packet data, so a crafted Smart Install message sent to TCP port 4786 can overflow a bu…KEVEPSS 99%analysed9.8CVE-2018-0151Cisco IOS/IOS XE QoS UDP Port 18999 Buffer OverflowCisco IOS and IOS XE contain a buffer overflow in the QoS subsystem caused by incorrect bounds checking of values in packets sent to UDP port 18999. …KEVEPSS 14%analysed9.8CVE-2017-12240Cisco IOS and IOS XE DHCP Relay Buffer Overflow RCEThe DHCP relay subsystem in Cisco IOS 12.2 through 15.6 and Cisco IOS XE contains a buffer overflow caused by improper input validation of DHCPv4 pac…KEVEPSS 14%analysed9.8CVE-2017-3881Cisco IOS/IOS XE CMP Telnet Option Handling RCECisco IOS and IOS XE fail to restrict CMP-specific Telnet options to internal cluster communications and mishandle malformed CMP Telnet options, so a…KEVEPSS 99%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.8CVE-2017-6736Cisco IOS and IOS XE SNMP buffer overflow remote code executionThe SNMP subsystem in Cisco IOS and IOS XE contains a buffer overflow that can be triggered by a crafted SNMP packet sent over IPv4 or IPv6. It affec…KEVEPSS 70%analysed8.8CVE-2017-6737Cisco IOS and IOS XE SNMP Buffer Overflow RCECisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMPv1, v2c, and v3. An authenticated remote attacker who know…KEVEPSS 45%analysed

Source: NIST National Vulnerability Database (record CVE-2017-6663), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.