← Back

CVE-2017-3849

nvd nist
Published: Mar 21, 2017Modified: May 13, 2026

JSON object

Loading...
7.4
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 4.0
Source: NVD

Description

A vulnerability in the Autonomic Networking Infrastructure (ANI) registrar feature of Cisco IOS Software (possibly 15.2 through 15.6) and Cisco IOS XE Software (possibly 3.7 through 3.18, and 16) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to incomplete input validation on certain crafted packets. An attacker could exploit this vulnerability by sending a crafted autonomic network channel discovery packet to a device that has all the following characteristics: (1) running a Cisco IOS Software or Cisco IOS XE Software release that supports the ANI feature; (2) configured as an autonomic registrar; (3) has a whitelist configured. An exploit could allow the attacker to cause the affected device to reload. Note: Autonomic networking should be configured with a whitelist. Do not remove the whitelist as a workaround. Cisco Bug IDs: CSCvc42717.

Affected (161)

Products: Cisco: Ios, Ios Xe
2 products
Ios
Ios Xe
Configuration A
161 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 15.2(3)e1
Version 15.2(3)e2
Version 15.2(3)e3
Version 15.2(3)e
Version 15.2(4)e1
Version 15.2(4)e2
Version 15.2(4)e3
Version 15.2(4)e
Version 15.2(5)e1
Version 15.2(5)e
Version 15.2(5a)e
Version 15.2(5b)e
Version 15.3(3)s1
Version 15.3(3)s2
Version 15.3(3)s3
Version 15.3(3)s4
Version 15.3(3)s5
Version 15.3(3)s6
Version 15.3(3)s8
Version 15.3(3)s9
Version 15.3(3)s
Version 15.4(1)s1
Version 15.4(1)s2
Version 15.4(1)s3
Version 15.4(1)s4
Version 15.4(1)s
Version 15.4(2)s1
Version 15.4(2)s2
Version 15.4(2)s3
Version 15.4(2)s4
Version 15.4(3)s1
Version 15.4(3)s2
Version 15.4(3)s3
Version 15.4(3)s4
Version 15.4(3)s5
Version 15.4(3)s6
Version 15.4(3)s6a
Version 15.4(3)s
Version 15.5(1)s1
Version 15.5(1)s2
Version 15.5(1)s3
Version 15.5(1)s4
Version 15.5(1)s
Version 15.5(2)s1
Version 15.5(2)s2
Version 15.5(2)s3
Version 15.5(2)s4
Version 15.5(2)s
Version 15.5(3)s0a
Version 15.5(3)s1
Version 15.5(3)s1a
Version 15.5(3)s2
Version 15.5(3)s3
Version 15.5(3)s4
Version 15.5(3)s5
Version 15.5(3)s
Version 15.5(3)sn
Version 15.6(1)s1
Version 15.6(1)s2
Version 15.6(1)s3
Version 15.6(1)s
Version 15.6(1)t0a
Version 15.6(1)t1
Version 15.6(1)t2
Version 15.6(1)t
Version 15.6(2)s1
Version 15.6(2)s2
Version 15.6(2)s
Version 15.6(2)sn
Version 15.6(2)sp1
Version 15.6(2)sp
Version 15.6(2)t1
Version 15.6(2)t2
Version 15.6(2)t
Version 15.6(3)m0a
Version 15.6(3)m1
Version 15.6(3)m
Cisco
Version 3.10.0s
Version 3.10.1s
Version 3.10.1xbs
Version 3.10.2s
Version 3.10.2ts
Version 3.10.3s
Version 3.10.4s
Version 3.10.5s
Version 3.10.6s
Version 3.10.7s
Version 3.10.8as
Version 3.10.8s
Version 3.11.0s
Version 3.11.1s
Version 3.11.2s
Version 3.11.3s
Version 3.11.4s
Version 3.12.0as
Version 3.12.1s
Version 3.12.2s
Version 3.12.3s
Version 3.12.4s
Version 3.13.0as
Version 3.13.0s
Version 3.13.1s
Version 3.13.2as
Version 3.13.2s
Version 3.13.3s
Version 3.13.4s
Version 3.13.5as
Version 3.13.5s
Version 3.13.6as
Version 3.13.6s
Version 3.14.0s
Version 3.14.1s
Version 3.14.2s
Version 3.14.3s
Version 3.14.4s
Version 3.15.0s
Version 3.15.1cs
Version 3.15.1s
Version 3.15.2s
Version 3.15.3s
Version 3.15.4s
Version 3.16.0cs
Version 3.16.0s
Version 3.16.1as
Version 3.16.1s
Version 3.16.2bs
Version 3.16.2s
Version 3.16.3as
Version 3.16.3s
Version 3.16.4as
Version 3.16.4bs
Version 3.16.4ds
Version 3.16.4s
Version 3.16.5s
Version 3.17.0s
Version 3.17.1as
Version 3.17.1s
Version 3.17.2s
Version 3.17.3s
Version 3.18.0as
Version 3.18.0s
Version 3.18.0sp
Version 3.18.1asp
Version 3.18.1bsp
Version 3.18.1csp
Version 3.18.1s
Version 3.18.1sp
Version 3.18.2s
Version 3.18.3vs
Version 3.7.0e
Version 3.7.1e
Version 3.7.2e
Version 3.7.3e
Version 3.7.4e
Version 3.7.5e
Version 3.8.0e
Version 3.8.1e
Version 3.8.2e
Version 3.8.3e
Version 3.9.0e
Version 3.9.1e

References (6)

Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.