A vulnerability in the Autonomic Networking feature of Cisconbsp;IOS XE Software could allow an unauthenticated, remote, autonomic node to access the Autonomic Networking infrastructure of an affected system, after the certificate for the autonomic node has been revoked.

The vulnerability exists because the affected software does not transfer certificate revocation listsnbsp;(CRLs) across Autonomic Control Planenbsp;(ACP) channels.

An attacker could exploit this vulnerability by connecting an autonomic node, which has a known and revoked certificate, to the autonomic domain of an affected system.

A successful exploit could allow the attacker to insert a previously trusted autonomic node into the autonomic domain of an affected system after the certificate for the node has been revoked.

There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170726-anicrl

Security Impact Rating: Medium

CVE: CVE-2017-6664

Leave a Reply