Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-6666


A vulnerability in the forwarding component of Cisco IOS XR Software for Cisco Network Convergence System (NCS) 5500 Series Routers could allow an authenticated, local attacker to cause the router to stop forwarding data traffic across Traffic Engineering (TE) tunnels, resulting in a denial of service (DoS) condition. More Information: CSCvd16665. Known Affected Releases: 6.2.11.BASE. Known Fixed Releases: 6.1.3 6.1.2 6.3.1.8i.BASE 6.2.11.8i.BASE 6.2.2.9i.BASE 6.1.32.11i.BASE 6.1.31.10i.BASE 6.1.4.3i.BASE.


Published

2017-06-13T06:29:00.973

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 6.0 (MEDIUM)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:N/I:N/A:P

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

3.4

Impact Score

2.9

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco ios_xr 6.0.0 Yes
Operating System cisco ios_xr 6.0.1 Yes
Operating System cisco ios_xr 6.0_base Yes
Operating System cisco ios_xr 6.1.0 Yes
Operating System cisco ios_xr 6.1.1 Yes
Operating System cisco ios_xr 6.1.2 Yes
Operating System cisco ios_xr 6.1.3 Yes
Operating System cisco ios_xr 6.2.0 Yes
Operating System cisco ios_xr 6.2.1 Yes

References