Vulnerability record · CVE-2017-6663 · published 7 August 2017
CVE-2017-6663: Cisco IOS/IOS XE Autonomic Networking DoS via node reload
Cisco · Ios
A flaw in the Autonomic Networking feature of Cisco IOS and IOS XE lets an unauthenticated, adjacent attacker force autonomic nodes to reload, producing a denial-of-service condition. The record names only Denali-16.2.1 and Denali-16.3.1 as known affected releases, and the CWE entry carries no specific weakness class. It matters because a single adjacent attacker can repeatedly disrupt routing and network availability without credentials.
Description
A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in a denial of service (DoS) condition. More Information: CSCvd88936. Known Affected Releases: Denali-16.2.1 Denali-16.3.1.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityThe flaw is unauthenticated and adjacent-reachable with high availability impact, and it is in CISA KEV, though the CVSS score is only 6.5 and EPSS is low.
What it is
A flaw in the Autonomic Networking feature of Cisco IOS and IOS XE lets an unauthenticated, adjacent attacker force autonomic nodes to reload, producing a denial-of-service condition. The record names only Denali-16.2.1 and Denali-16.3.1 as known affected releases, and the CWE entry carries no specific weakness class. It matters because a single adjacent attacker can repeatedly disrupt routing and network availability without credentials.
Impact
The attacker can cause affected autonomic nodes to reload, taking them out of service and disrupting network availability for as long as the attack is repeated. No confidentiality or integrity impact is described; the effect is availability only.
Attack surface
Reached from an adjacent network position (AV:A) with no authentication (PR:N) and no user interaction (UI:N), per the CVSS vector. The description does not state which protocol or packet triggers the reload, so the exact adjacent vector is not detailed in this record.
Exploitation
CVE-2017-6663 is listed in CISA KEV (added 2022-03-03, due 2022-03-24), indicating known exploitation, while EPSS is low at roughly 2.1 percent (81st percentile). No ransomware campaign use is recorded, and the reference tags are vendor advisory, VDB entries and a US government resource.
What to do
- Apply the Cisco IOS/IOS XE updates referenced in the vendor advisory cisco-sa-20170726-anidos, prioritizing Denali-16.2.1 and Denali-16.3.1 systems.
- If Autonomic Networking is not required, disable it on affected devices to remove the exposed feature.
- Restrict and monitor adjacent-layer access to autonomic-capable network segments so untrusted hosts cannot reach them.
- Track KEV remediation deadlines for any remaining unpatched devices and schedule upgrades accordingly.
Detection
- Alert on unexpected reload or restart events on Cisco IOS/IOS XE devices running Autonomic Networking, correlated with adjacency changes.
- Monitor for repeated, unexplained node reloads across autonomic domains that could indicate a sustained DoS attempt.
- Review logs for anomalous traffic from adjacent hosts toward autonomic-capable interfaces, since the record does not specify the triggering packet.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-6663 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/99973 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038999 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170726-anidos | Vendor Advisory |
| http://www.securityfocus.com/bid/99973 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038999 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170726-anidos | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6663 | US Government Resource |
Track CVE-2017-6663 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-6663), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.