Evidence dossier

CVE-2017-6627

A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote attacker to cause the input…

Exploited in the wild (CISA KEV since Mar 3, 2022). NVD reports CVSS 3.1 7.5. EPSS estimates 6.0% exploit likelihood as of Aug 27, 2026.

67.268.5Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and a denial of service (DoS) condition. The vulnerability is due to Cisco IOS Software application changes that create UDP sockets and leave the sockets idle without closing them. An attacker could exploit this vulnerability by sending UDP packets with a destination port of 0 to an affected device. A successful exploit could allow the attacker to cause UDP packets to be held in the input interfaces queue, resulting in a DoS condition. The input interface queue will stop holding UDP packets when it receives 250 packets. Cisco Bug IDs: CSCup10024, CSCva55744, CSCva95506.

State
PUBLISHED
Published
Sep 7, 2017
Updated
Oct 21, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    cisco

    Record text: A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and a denial of service (DoS) condition. The vulnerability is due to Cisco IOS Software application changes that create UDP sockets and leave the sockets idle without closing them. An attacker could exploit this vulnerability by sending UDP packets with a destination port of 0 to an affected device. A successful exploit could allow the attacker to cause UDP packets to be held in the input interfaces queue, resulting in a DoS condition. The input interface queue will stop holding UDP packets when it receives 250 packets. Cisco Bug IDs: CSCup10024, CSCva55744, CSCva95506.

    Inspect raw assertion
    Field
    container
    Value
    A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and a denial of service (DoS) condition. The vulnerability is due to Cisco IOS Software application changes that create UDP sockets and leave the sockets idle without closing them. An attacker could exploit this vulnerability by sending UDP packets with a destination port of 0 to an affected device. A successful exploit could allow the attacker to cause UDP packets to be held in the input interfaces queue, resulting in a DoS condition. The input interface queue will stop holding UDP packets when it receives 250 packets. Cisco Bug IDs: CSCup10024, CSCva55744, CSCva95506.
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 6.04% probability · 92.83th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.060420000000; percentile 0.928300000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Mar 3, 2022 · first observed Jul 19, 2026

Exploit likelihood6.04%

FIRST EPSS · score date Aug 27, 2026 · 92.8th percentile · first observed Aug 27, 2026

SeverityCVSS 7.5

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

Outside this view’s verified evidence

Reason detail begins outside this selected snapshot; the state remains source-bound.

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
ciscoOriginal assertion
Record text

A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and a denial of service (DoS) condition. The vulnerability is due to Cisco IOS Software application changes that create UDP sockets and leave the sockets idle without closing them. An attacker could exploit this vulnerability by sending UDP packets with a destination port of 0 to an affected device. A successful exploit could allow the attacker to cause UDP packets to be held in the input interfaces queue, resulting in a DoS condition. The input interface queue will stop holding UDP packets when it receives 250 packets. Cisco Bug IDs: CSCup10024, CSCva55744, CSCva95506.

Inspect raw assertion
Field
container
Value
A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and a denial of service (DoS) condition. The vulnerability is due to Cisco IOS Software application changes that create UDP sockets and leave the sockets idle without closing them. An attacker could exploit this vulnerability by sending UDP packets with a destination port of 0 to an affected device. A successful exploit could allow the attacker to cause UDP packets to be held in the input interfaces queue, resulting in a DoS condition. The input interface queue will stop holding UDP packets when it receives 250 packets. Cisco Bug IDs: CSCup10024, CSCva55744, CSCva95506.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

6.04% probability · 92.83th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.060420000000; percentile 0.928300000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
71Underlying assertions
2Canonical products
71Target assertions
0Constraint assertions

Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

3 scope groups

cisco · source assertedn/aCisco IOS and Cisco IOS XEDirect source scope
Affected: Cisco IOS and Cisco IOS XE
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "Cisco IOS and Cisco IOS XE"}]
NVD CPE · OPERATING SYSTEMciscoiosVulnerable target · 35 assertions
Version 15.1(2)gc; Version 15.1(2)gc1; Version 15.1(2)gc2; Version 15.1(4)gc; Version 15.1(4)gc1; Version 15.1(4)gc2; Version 15.2(1)gc; Version 15.2(1)gc1; Version 15.2(1)gc2; Version 15.2(2)gc; Version 15.2(3)gc; Version 15.2(3)gc1; Version 15.2(3r)gca; Version 15.2(4)gc; Version 15.2(4)gc1; Version 15.2(4)gc2; Version 15.2(4)gc3; Version 15.4(1)t; Version 15.4(1)t1; Version 15.4(1)t2; Version 15.4(1)t3; Version 15.4(1)t4; Version 15.4(2)t; Version 15.4(2)t1; Version 15.4(2)t2; Version 15.4(3)m; Version 15.4(3)m1; Version 15.4(3)m2; Version 15.4(3)m2.2; Version 15.4(3)m3; Version 15.4(3)m4; Version 15.4(3)m5; Version 15.4(3)m6; Version 15.4(3)m6a; Version 15.4(3)m7Canonical identity product-5972f4392170d0d1b4e75a10eb3b383835ead601c8d9b09329525407a4e1471aLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:cisco:ios:15.2\(4\)gc1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f6fe61c7-3b61-4085-ad91-137459da29d0
  2. cpe:2.3:o:cisco:ios:15.4\(3\)m5:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 31
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2b8fb86f-2a89-413b-bed7-97e3d392804e
  3. cpe:2.3:o:cisco:ios:15.4\(2\)t1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    100da24f-464e-4273-83df-6428d0ed6641
  4. cpe:2.3:o:cisco:ios:15.4\(1\)t2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    caf02c8e-9bb2-4dc2-8bf1-932835191f09
  5. cpe:2.3:o:cisco:ios:15.4\(3\)m2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 27
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    88f41406-0f55-4d74-a4f6-4abd5a803907
  6. cpe:2.3:o:cisco:ios:15.4\(3\)m:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 25
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1c85baaf-819b-40e7-9099-04aa8d9ab114
  7. cpe:2.3:o:cisco:ios:15.1\(4\)gc2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b082c941-ce02-440f-8dd7-87873504b964
  8. cpe:2.3:o:cisco:ios:15.4\(3\)m2.2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 28
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8cf9c9ae-b5a6-4b03-9ed9-fdbb40ce5bb9
  9. cpe:2.3:o:cisco:ios:15.2\(4\)gc:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e3714e18-9a21-4d04-bb5e-0299af443e2e
  10. cpe:2.3:o:cisco:ios:15.4\(2\)t2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    063c0c47-25eb-4aa4-9332-8e43cd60ff39
  11. cpe:2.3:o:cisco:ios:15.2\(3r\)gca:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cb015852-a945-4801-93aa-6c562afab80d
  12. cpe:2.3:o:cisco:ios:15.1\(2\)gc2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ed4ecf5c-1b91-4b54-bab4-2df17a1bbf56
  13. cpe:2.3:o:cisco:ios:15.2\(2\)gc:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c89d14bc-1718-4ae9-b107-1709c2ce965e
  14. cpe:2.3:o:cisco:ios:15.2\(4\)gc3:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cf10596d-457a-4da8-8037-5e92e1d39232
  15. cpe:2.3:o:cisco:ios:15.2\(3\)gc:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d80852ce-8d91-4e85-a97f-c7a9af5278ca
  16. cpe:2.3:o:cisco:ios:15.1\(2\)gc1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    242a4dc2-c9c7-4acb-99f0-317959b0ca2d
  17. cpe:2.3:o:cisco:ios:15.4\(3\)m7:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 34
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fb998a1f-baea-4b8f-be49-1c282ed3952e
  18. cpe:2.3:o:cisco:ios:15.4\(3\)m3:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 29
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7082c083-7517-4cd4-bf95-cc7af08d4053
  19. cpe:2.3:o:cisco:ios:15.1\(4\)gc1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5aad9b95-0d54-49ca-824d-68175d6b4a8e
  20. cpe:2.3:o:cisco:ios:15.2\(1\)gc2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0318bb57-8001-4f2a-954c-ad8db2a94356
  21. cpe:2.3:o:cisco:ios:15.4\(3\)m6:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 32
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    005ead76-34be-4e3f-8840-23f613661fe8
  22. cpe:2.3:o:cisco:ios:15.2\(1\)gc:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    98eb6a3f-ddab-4fc6-a857-6e106e815505
  23. cpe:2.3:o:cisco:ios:15.4\(1\)t3:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2c1b86d1-344a-470d-8a35-bd8a9abe9d9a
  24. cpe:2.3:o:cisco:ios:15.4\(1\)t4:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c5ac88eb-7a67-4cde-9c69-94734966e677
  25. cpe:2.3:o:cisco:ios:15.4\(2\)t:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    74e1226b-46cf-4c82-911a-86c818a75dfa
  26. cpe:2.3:o:cisco:ios:15.1\(2\)gc:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3cf70487-4e51-4570-927b-1b74d73e9d58
  27. cpe:2.3:o:cisco:ios:15.4\(1\)t1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c1ee552e-226c-46de-9861-cb148ad8fb44
  28. cpe:2.3:o:cisco:ios:15.1\(4\)gc:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1cd00484-39d2-4cd5-abea-3c5ad9977bb6
  29. cpe:2.3:o:cisco:ios:15.2\(4\)gc2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    71080d8b-bc81-4cdf-8626-d0f35da40aea
  30. cpe:2.3:o:cisco:ios:15.4\(3\)m1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 26
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ed684db4-527a-4268-b197-4719b0178429
  31. cpe:2.3:o:cisco:ios:15.4\(1\)t:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a0b856bb-0ffe-4a92-9ce7-d71b6c611cd3
  32. cpe:2.3:o:cisco:ios:15.4\(3\)m4:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 30
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    370ef3dc-151f-4724-a026-3ad8ed6d801c
  33. cpe:2.3:o:cisco:ios:15.4\(3\)m6a:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 33
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2595b3e3-7fd4-4eff-98a2-89156a657a0e
  34. cpe:2.3:o:cisco:ios:15.2\(1\)gc1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7741d6e0-2507-44d9-8476-ae11dadec611
  35. cpe:2.3:o:cisco:ios:15.2\(3\)gc1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    af777880-43bf-4d4a-9ba1-b2e925b5de11
NVD CPE · OPERATING SYSTEMciscoios_xeVulnerable target · 36 assertions
Version 3.14.0s; Version 3.14.1s; Version 3.14.2s; Version 3.14.3s; Version 3.14.4s; Version 3.15.0s; Version 3.15.1cs; Version 3.15.1s; Version 3.15.2s; Version 3.15.3s; Version 3.15.4s; Version 3.16.0cs; Version 3.16.0s; Version 3.16.1as; Version 3.16.1s; Version 3.16.2as; Version 3.16.2bs; Version 3.16.2s; Version 3.16.3as; Version 3.16.3s; Version 3.16.4as; Version 3.16.4bs; Version 3.16.4ds; Version 3.16.4s; Version 3.16.5s; Version 3.16.6s; Version 3.17.0s; Version 3.17.1as; Version 3.17.1s; Version 3.17.3s; Version 3.18.0as; Version 3.18.0s; Version 3.18.1s; Version 3.18.2s; Version 3.18.3s; Version 3.18.3vsCanonical identity product-cc06181059d0f387414dd5737700c03a38fe93d65d4a541ac9744a37c25c9f59Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:cisco:ios_xe:3.14.3s:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 38
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    579c9e7f-6ae4-4df5-abcf-db390e4669e6
  2. cpe:2.3:o:cisco:ios_xe:3.15.0s:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 40
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fad93cd1-4188-40b7-a20e-9c3fe8344a27
  3. cpe:2.3:o:cisco:ios_xe:3.18.3s:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 69
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4063ccf8-19be-4411-b71b-147bb146700b
  4. cpe:2.3:o:cisco:ios_xe:3.16.1s:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 49
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d3822447-eb80-4df2-b7f2-471f55ba99c0
  5. cpe:2.3:o:cisco:ios_xe:3.16.4bs:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 56
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c35b3f96-b342-4afc-a511-7a735b961ecd
  6. cpe:2.3:o:cisco:ios_xe:3.17.1as:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 62
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1aef94c7-cee6-4696-9f1d-549639a831c2
  7. cpe:2.3:o:cisco:ios_xe:3.15.1s:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 42
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2972e680-5a19-4858-9b35-0b959ed319a3
  8. cpe:2.3:o:cisco:ios_xe:3.18.1s:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 67
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6bebcbf7-d1cf-488f-bb3e-f864f901a96a
  9. cpe:2.3:o:cisco:ios_xe:3.15.1cs:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 41
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0eeab7f8-eab5-4e7a-8a1b-38ec16d601fb
  10. cpe:2.3:o:cisco:ios_xe:3.14.2s:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 37
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e61e0102-b9b6-41f4-9041-0a5f144d849a
  11. cpe:2.3:o:cisco:ios_xe:3.16.1as:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 48
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ac72aa6d-9e18-49f7-95ca-a4a5d7a60e4e
  12. cpe:2.3:o:cisco:ios_xe:3.16.2as:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 50
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ba0b441a-3a09-4a58-8a40-d463003a50bc
  13. cpe:2.3:o:cisco:ios_xe:3.16.4s:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 58
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9fbef4b2-ea12-445a-823e-e0e5343a405e
  14. cpe:2.3:o:cisco:ios_xe:3.16.4ds:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 57
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ded2d791-4142-4b9e-8401-6b63357536b0
  15. cpe:2.3:o:cisco:ios_xe:3.17.3s:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 64
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    141ffb5e-ea72-4fc1-b87a-b5e2d5fcfe2a
  16. cpe:2.3:o:cisco:ios_xe:3.18.0s:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 66
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ee81aa43-88d4-4efc-b8f6-a41eff437819
  17. cpe:2.3:o:cisco:ios_xe:3.14.4s:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 39
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2a076e1f-3457-410a-8ab6-64416ecb20a7
  18. cpe:2.3:o:cisco:ios_xe:3.18.0as:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 65
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    be390091-d382-4436-bbb4-d4c33e4f6714
  19. cpe:2.3:o:cisco:ios_xe:3.16.0s:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 47
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a0e5bb91-b5e7-4961-87dc-26596e5eded7
  20. cpe:2.3:o:cisco:ios_xe:3.16.5s:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 59
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    844e7cec-5cb6-47ae-95f7-75693347c08e
  21. cpe:2.3:o:cisco:ios_xe:3.17.1s:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 63
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    876767c7-0196-4226-92b1-dde851b53655
  22. cpe:2.3:o:cisco:ios_xe:3.16.3s:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 54
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1826c997-6d5d-480e-a12e-3048b6c61216
  23. cpe:2.3:o:cisco:ios_xe:3.16.4as:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 55
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5d136c95-f837-49ad-82b3-81c25f68d0eb
  24. cpe:2.3:o:cisco:ios_xe:3.18.2s:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 68
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bd8cca19-1d1c-45c0-a1a0-ced5885ad580
  25. cpe:2.3:o:cisco:ios_xe:3.15.4s:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 45
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5c5484a4-d116-4b79-8369-47979e20aaca
  26. cpe:2.3:o:cisco:ios_xe:3.14.1s:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 36
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b9247665-bbe7-4def-b97b-4981a0ea5ce4
  27. cpe:2.3:o:cisco:ios_xe:3.16.3as:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 53
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7eefd3ad-efa2-4808-801e-b98e4c63aa76
  28. cpe:2.3:o:cisco:ios_xe:3.17.0s:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 61
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    12793f39-13c4-4dbc-9b78-fe361bddf89d
  29. cpe:2.3:o:cisco:ios_xe:3.15.3s:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 44
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d0ec9a19-26e6-4e69-b4e7-852cb6327ead
  30. cpe:2.3:o:cisco:ios_xe:3.18.3vs:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 70
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fa08c168-48be-41ed-a3bd-87bae27a1351
  31. cpe:2.3:o:cisco:ios_xe:3.16.6s:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 60
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    147a245e-9a5d-4178-a1ac-5b0d41c3b730
  32. cpe:2.3:o:cisco:ios_xe:3.16.2bs:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 51
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    51e1a64a-204d-4567-a2dc-efeb2ae62b54
  33. cpe:2.3:o:cisco:ios_xe:3.15.2s:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 43
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f1bfe916-916f-4936-a331-21a0e8193920
  34. cpe:2.3:o:cisco:ios_xe:3.16.2s:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 52
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    970fd986-6d0e-441c-9bf3-c66a25763a7a
  35. cpe:2.3:o:cisco:ios_xe:3.16.0cs:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 46
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5568eabf-8f43-4a87-8de4-a03e9065be53
  36. cpe:2.3:o:cisco:ios_xe:3.14.0s:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 35
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fd803f59-1cd2-4ca9-9eb1-3cc4abcd9547

Affected-product evidence

Accepted scope and product mapping

0 canonical links · 0 source-reported links

Applicability remains source-scoped; safety and exposure remain unassessed.

Assessments

CVSS by origin

7.5
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
5.0
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:L/Au:N/C:N/I:N/A:P
7.5
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
7.5
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.