CVE-2017-6737
KEVmassCisco IOS/IOS XE SNMP memory-corruption bug allows authenticated remote code execution
CISA: Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
CVE-2017-6737 is a memory-corruption flaw (CWE-119) in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE that allows an authenticated, remote attacker to execute arbitrary code on an affected device. It is triggered by sending crafted SNMP packets to a device where SNMP is enabled; the attacker must already hold valid SNMP credentials, such as a community string or an SNMPv3 user. Successful exploitation yields remote code execution on the router or switch itself, potentially giving the attacker control of a core network device. Any organization running affected Cisco IOS or IOS XE software with SNMP enabled is exposed, with the exact vulnerable release ranges defined in Cisco's advisory. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-03 (ransomware use unknown), and EPSS estimates a 44.3% probability of exploitation in the next 30 days (99th percentile); no public proof-of-concept is known.
What to do: Upgrade all Cisco IOS and IOS XE devices to a fixed release per Cisco's advisory, as CISA's KEV required action mandates, prioritizing internet-facing and management-plane devices. Until patched, restrict SNMP access to trusted management hosts with ACLs and harden or rotate SNMP community strings and SNMPv3 credentials, since valid credentials are required for exploitation. Inventory which devices have SNMP enabled and review logs for unexpected SNMP traffic from unknown sources.
| Cisco IOS Software | — |
| Cisco IOS XE Software | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device. The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or earlier) or the user credentials (SNMPv3). An exploit could allow the attacker to execute arbitrary code and obtain full control of the system or to cause a reload of the affected system. Only traffic directed to the affected system can be used to exploit this vulnerability.
- Affected
- Cisco IOS and IOS XE Software
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- ios, ios xe
- Weakness
- CWE-119
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.