PatchSiren cyber security CVE debrief
CVE-2017-3824 Cisco CVE debrief
CVE-2017-3824 is a denial-of-service vulnerability in Cisco cBR Series Converged Broadband Routers. According to Cisco and NVD, an unauthenticated remote attacker can abuse list header handling to trigger a device reload. The impact is service disruption rather than direct code execution, but the affected router is infrastructure-critical, so even a reload can be operationally significant.
- Vendor
- Cisco
- Product
- Unknown
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-03
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-03
- Advisory updated
- 2026-05-13
Who should care
Cisco cBR-8 Converged Broadband Router owners, network operations teams, and security teams responsible for Cisco IOS XE lifecycle management should prioritize this issue, especially if vulnerable releases are still deployed in production broadband edge environments.
Technical summary
NVD describes the flaw as a weakness in Cisco IOS XE list header handling affecting Cisco cBR-8 Converged Broadband Routers. The reported consequence is a remotely triggered reload leading to denial of service. NVD assigns CWE-119 and lists CVSS 3.0 6.8 (AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H). Cisco’s description names affected releases 15.5(3)S and 15.6(1)S, with fixed releases including 15.5(3)S2, 15.6(1)S1, 15.6(2)S, 15.6(2)SP, and 16.4(1).
Defensive priority
Medium-High
Recommended defensive actions
- Identify Cisco cBR-8 Converged Broadband Routers in your environment and inventory the installed Cisco IOS XE release.
- Compare installed versions with the known affected and fixed releases listed by Cisco and NVD.
- Upgrade to a fixed Cisco IOS XE release from Cisco’s advisory guidance as soon as operationally feasible.
- Validate that maintenance and rollback procedures are ready before changing router software on production broadband infrastructure.
- Monitor affected devices for unexpected reloads or other denial-of-service symptoms until remediation is complete.
Evidence notes
This debrief is based on the supplied Cisco/NVD corpus: the NVD record published on 2017-02-03 and modified on 2026-05-13, the Cisco vendor advisory reference linked by NVD, and the NVD CVSS/CWE data. The supported facts are limited to unauthenticated remote DoS via list header handling on Cisco cBR-8 routers running vulnerable IOS XE releases.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-3824 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-3824
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-3824 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-3824
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170201-cbr
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.