CVE-2017-6664
Summary
| CVE | CVE-2017-6664 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-08-07 06:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | A vulnerability in the Autonomic Networking feature of Cisco IOS XE Software could allow an unauthenticated, remote, autonomic node to access the Autonomic Networking infrastructure of an affected system, after the certificate for the autonomic node has been revoked. This vulnerability affected devices that are running Release 16.x of Cisco IOS XE Software and are configured to use Autonomic Networking. This vulnerability does not affect devices that are running an earlier release of Cisco IOS XE Software or devices that are not configured to use Autonomic Networking. More Information: CSCvd22328. Known Affected Releases: 15.5(1)S3.1 Denali-16.2.1. |
Risk And Classification
Primary CVSS: v3.0 7.5 HIGH from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Problem Types: CWE-295 | Certificate Revocation Vulnerability
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 7.5 | HIGH | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
| 2.0 | [email protected] | Primary | 5 | AV:N/AC:L/Au:N/C:N/I:P/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
HighAvailability
NoneCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Cisco | Ios Xe | 16.5.1c | All | All | All |
| Operating System | Cisco | Ios Xe | 16.6.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 3.10.8as | All | All | All |
| Operating System | Cisco | Ios Xe | 3.10.8s | All | All | All |
| Operating System | Cisco | Ios Xe | 3.12.0s | All | All | All |
| Operating System | Cisco | Ios Xe | 3.12.1s | All | All | All |
| Operating System | Cisco | Ios Xe | 3.12.2s | All | All | All |
| Operating System | Cisco | Ios Xe | 3.12.3s | All | All | All |
| Operating System | Cisco | Ios Xe | 3.12.4s | All | All | All |
| Operating System | Cisco | Ios Xe | 3.13.1s | All | All | All |
| Operating System | Cisco | Ios Xe | 3.13.2s | All | All | All |
| Operating System | Cisco | Ios Xe | 3.13.4s | All | All | All |
| Operating System | Cisco | Ios Xe | 3.13.5s | All | All | All |
| Operating System | Cisco | Ios Xe | 3.14.0s | All | All | All |
| Operating System | Cisco | Ios Xe | 3.14.1s | All | All | All |
| Operating System | Cisco | Ios Xe | 3.14.2s | All | All | All |
| Operating System | Cisco | Ios Xe | 3.14.3s | All | All | All |
| Operating System | Cisco | Ios Xe | 3.14.4s | All | All | All |
| Operating System | Cisco | Ios Xe | 3.15.0s | All | All | All |
| Operating System | Cisco | Ios Xe | 3.15.1s | All | All | All |
| Operating System | Cisco | Ios Xe | 3.15.2s | All | All | All |
| Operating System | Cisco | Ios Xe | 3.15.3s | All | All | All |
| Operating System | Cisco | Ios Xe | 3.16.0s | All | All | All |
| Operating System | Cisco | Ios Xe | 3.16.1as | All | All | All |
| Operating System | Cisco | Ios Xe | 3.16.2as | All | All | All |
| Operating System | Cisco | Ios Xe | 3.16.2s | All | All | All |
| Operating System | Cisco | Ios Xe | 3.17.0s | All | All | All |
| Operating System | Cisco | Ios Xe | 3.17.1s | All | All | All |
| Operating System | Cisco | Ios Xe | 3.18.0s | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | Cisco IOS XE | affected Cisco IOS XE | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco IOS XE Software CVE-2017-6664 Certificate Validation Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Cisco IOS XE Software Autonomic Networking Infrastructure Certificate Revocation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | Vendor Advisory |
| Cisco IOS/IOS XE Autonomic Networking Validation Flaw Lets Remote Users Bypass the Certificate Revocation List - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.