ZeroHour

CVE-2017-6738

KEVmass

SNMP Buffer Overflow Enables Authenticated RCE in Cisco IOS and IOS XE

CISA: Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

CVSS 3.1
8.8 high
EPSS
11%p96
Published
()
KEV added
AI analysis

CVE-2017-6738 is a buffer overflow in the SNMP subsystem of Cisco IOS and IOS XE that allows an authenticated remote attacker to execute arbitrary code or cause an affected device to reload by sending a crafted SNMP packet over IPv4 or IPv6. Exploitation requires traffic directed to the device and knowledge of the SNMP read-only community string (SNMPv1/v2c) or valid SNMPv3 user credentials, but a successful attack can yield full control of the system. All versions of SNMP (1, 2c, and 3) are affected, and any IOS or IOS XE device with SNMP enabled that has not explicitly excluded the affected MIBs/OIDs should be considered vulnerable. The flaw carries high severity (CVSS 8.8), a high likelihood of exploitation (EPSS ~10.7%, 96th percentile), and it has been added to CISA's Known Exploited Vulnerabilities catalog (March 3, 2022), confirming exploitation in the wild. Workarounds are available, but the required action is to apply updates per vendor instructions.

What to do: Upgrade affected IOS and IOS XE devices to a fixed release identified via Cisco's IOS Software Checker, per the CISA KEV required action. As an interim measure, apply Cisco's documented workarounds: restrict SNMP access to trusted hosts with ACLs, exclude the affected MIBs/OIDs, or disable SNMP entirely if not required. Prioritize internet-facing and edge devices, and inventory for SNMP v1/v2c community strings and v3 accounts on exposed systems.

Affected
Cisco IOSAll versions running SNMP v1, 2c, or 3 where SNMP is enabled and the affected MIBs/OIDs have not been explicitly excluded (fixed releases per Cisco; use the Cis
Cisco IOS XEAll versions running SNMP v1, 2c, or 3 where SNMP is enabled and the affected MIBs/OIDs have not been explicitly excluded (fixed releases per Cisco; use the Cis
Estimated exposure
masshundreds of thousands to millions of devices (Cisco IOS/IOS XE powers a large share of the world's enterprise routers and switches; public internet scans have… — Estimated from the ubiquity of Cisco IOS/IOS XE as the dominant network OS in enterprise and service-provider routing/switching and from public scan counts of internet-exposed Cisco devices, noting that any device with SNMP enabled and the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP - Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or earlier, the attacker must know the SNMP read-only community string for the affected system. To exploit these vulnerabilities via SNMP Version 3, the attacker must have user credentials for the affected system. A successful exploit could allow the attacker to execute arbitrary code and obtain full control of the affected system or cause the affected system to reload. Customers are advised to apply the workaround as contained in the Workarounds section below. Fixed software information is available via the Cisco IOS Software Checker. All devices that have enabled SNMP and have not explicitly excluded the affected MIBs or OIDs should be considered vulnerable. There are workarounds that address these vulnerabilities.

CISA Known Exploited Vulnerability
Affected
Cisco IOS and IOS XE Software
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
ios, ios xe
Weakness
CWE-119
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.