5
CVSSv2

CVE-2017-6664

Published: 07/08/2017 Updated: 03/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

A vulnerability in the Autonomic Networking feature of Cisco IOS XE Software could allow an unauthenticated, remote, autonomic node to access the Autonomic Networking infrastructure of an affected system, after the certificate for the autonomic node has been revoked. The vulnerability exists because the affected software does not transfer certificate revocation lists (CRLs) across Autonomic Control Plane (ACP) channels. An attacker could exploit this vulnerability by connecting an autonomic node, which has a known and revoked certificate, to the autonomic domain of an affected system. A successful exploit could allow the malicious user to insert a previously trusted autonomic node into the autonomic domain of an affected system after the certificate for the node has been revoked. There are no workarounds that address this vulnerability. This advisory is available at the following link: tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170726-anicrl

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios xe 3.15.2s

cisco ios xe 3.17.0s

cisco ios xe 3.13.4s

cisco ios xe 3.16.2as

cisco ios xe 3.16.1as

cisco ios xe 3.14.2s

cisco ios xe 3.15.1s

cisco ios xe 3.16.0s

cisco ios xe 3.12.4s

cisco ios xe 3.13.5s

cisco ios xe 3.15.3s

cisco ios xe 3.10.8s

cisco ios xe 3.18.0s

cisco ios xe 3.12.3s

cisco ios xe 3.14.1s

cisco ios xe 16.5.1c

cisco ios xe 3.12.0s

cisco ios xe 3.12.1s

cisco ios xe 3.17.1s

cisco ios xe 3.13.1s

cisco ios xe 16.6.1

cisco ios xe 3.13.2s

cisco ios xe 3.15.0s

cisco ios xe 3.10.8as

cisco ios xe 3.14.3s

cisco ios xe 3.14.4s

cisco ios xe 3.16.2s

cisco ios xe 3.12.2s

cisco ios xe 3.14.0s

Vendor Advisories

A vulnerability in the Autonomic Networking feature of Cisco IOS XE Software could allow an unauthenticated, remote, autonomic node to access the Autonomic Networking infrastructure of an affected system, after the certificate for the autonomic node has been revoked The vulnerability exists because the affected software does not transfer certific ...