AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-6606

MEDIUM · CVSS 6.4 EPSS 0.50%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-04-07 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.4. It affects Cisco. Exploitation may require the attacker to be authenticated.

CVE
CVE-2017-6606
Severity
MEDIUM
CVSS
6.4
EPSS
0.50%
Cisco

Original NVD Description

A vulnerability in a startup script of Cisco IOS XE Software could allow an unauthenticated attacker with physical access to the targeted system to execute arbitrary commands on the underlying operating system with the privileges of the root user. More Information: CSCuz06639 CSCuz42122. Known Affected Releases: 15.6(1.1)S 16.1.2 16.2.0 15.2(1)E. Known Fixed Releases: Denali-16.1.3 16.2(1.8) 16.1(2.61) 15.6(2)SP 15.6(2)S1 15.6(1)S2 15.5(3)S3a 15.5(3)S3 15.5(2)S4 15.5(1)S4 15.4(3)S6a 15.4(3)S6 15.3(3)S8a 15.3(3)S8 15.2(5)E 15.2(4)E3 15.2(3)E5 15.0(2)SQD3 15.0(1.9.2)SQD3 3.9(0)E.

Related CVEs

Other vulnerabilities affecting the same vendor(s)