CVE-2017-6606 describes a vulnerability in a startup script of Cisco IOS XE Software, allowing an unauthenticated attacker with physical access to execute arbitrary commands as root. The CVSS score of 6.4 (MEDIUM) indicates a high impact on confidentiality, integrity, and availability, despite requiring physical access and having high attack complexity. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog. This suggests a lower immediate threat despite the severe potential impact if exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.1.0sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.1.0s:*:*:*:*:*:*:* | ||
3.1.0sgCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.1.0sg:*:*:*:*:*:*:* | ||
3.1.1sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.1.1s:*:*:*:*:*:*:* | ||
3.1.1sgCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.1.1sg:*:*:*:*:*:*:* | ||
3.1.2sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.1.2s:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.