CVE-2017-3849 is a denial-of-service vulnerability in the Autonomic Networking Infrastructure (ANI) registrar feature of Cisco IOS and IOS XE Software. An unauthenticated, adjacent attacker can exploit incomplete input validation by sending a crafted autonomic network channel discovery packet, causing the affected device to reload. With a CVSS score of 7.4 (High), this vulnerability has an adjacent attack vector and low attack complexity, leading to a high impact on availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, though it received limited media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.2\(3\)eCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(3\)e:*:*:*:*:*:*:* | ||
15.2\(3\)e1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(3\)e1:*:*:*:*:*:*:* | ||
15.2\(3\)e2CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(3\)e2:*:*:*:*:*:*:* | ||
15.2\(3\)e3CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(3\)e3:*:*:*:*:*:*:* | ||
15.2\(4\)eCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(4\)e:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.