Cisco IOS XE Software Autonomic Networking Infrastructure Certificate Revocation (cisco-sa-20170726-anicrl)

high Nessus Plugin ID 131131

Synopsis

The remote device is is affected by a vulnerability.

Description

According to its self-reported version, Cisco IOS XE Software is affected by a vulnerability in the Autonomic Networking feature because the affected software does not transfer certificate revocation lists (CRLs) across Autonomic Control Plane (ACP) channels. An unauthenticated, remote attacker can exploit this, by connecting an autonomic node that has a known and revoked certificate to the autonomic domain of an affected system. The attacker can then insert a previously trusted autonomic node into the autonomic domain of an affected system after the certificate for the node has been revoked.

Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

No fixes are available for this vulnerability. For more information, see Cisco bug ID CSCvd22328

See Also

http://www.nessus.org/u?21f85a5a

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvd22328

Plugin Details

Severity: High

ID: 131131

File Name: cisco-sa-20170726-anicrl.nasl

Version: 1.9

Type: combined

Family: CISCO

Published: 11/20/2019

Updated: 5/3/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2017-6664

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:cisco:ios_xe

Required KB Items: Host/Cisco/IOS-XE/Version

Exploit Ease: No known exploits are available

Patch Publication Date: 7/26/2017

Vulnerability Publication Date: 8/7/2017

Reference Information

CVE: CVE-2017-6664

BID: 99986

CISCO-SA: cisco-sa-20170726-anicrl

CISCO-BUG-ID: CSCvd22328