CVE-2017-3850 is a denial-of-service (DoS) vulnerability in the Autonomic Networking Infrastructure (ANI) feature of Cisco IOS and IOS XE Software, affecting versions 15.4-15.6 and 3.7-3.18/16 respectively. It stems from incomplete input validation of crafted IPv6 packets, allowing an unauthenticated, remote attacker to cause a device reload. Rated Medium (CVSS 5.9), exploitation requires a reachable IPv6 interface and is considered high complexity due to specific packet crafting. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, though it received limited media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.2\(3\)eCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(3\)e:*:*:*:*:*:*:* | ||
15.2\(3\)e1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(3\)e1:*:*:*:*:*:*:* | ||
15.2\(3\)e2CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(3\)e2:*:*:*:*:*:*:* | ||
15.2\(3\)e3CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(3\)e3:*:*:*:*:*:*:* | ||
15.2\(4\)eCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(4\)e:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.