CVE-2017-6739
KEVmassBuffer Overflow in Cisco IOS/IOS XE SNMP Allows Authenticated RCE
CISA: Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
CVE-2017-6739 is a buffer overflow (CWE-119) in the SNMP implementation of Cisco IOS and IOS XE that allows an authenticated, remote attacker to execute arbitrary code or cause a device reload. It is triggered by sending a crafted SNMP packet directed at the affected device, and the attacker must already know the SNMP read-only community string (v1/v2c) or valid SNMPv3 user credentials; the flaw affects all SNMP versions (1, 2c, and 3). Successful code execution gives the attacker full control of the router or switch, while a simpler exploit path causes a denial-of-service reload. Any organization running Cisco IOS or IOS XE with SNMP enabled is potentially affected, which given Cisco's dominance in enterprise networking represents a very large installed base. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), confirming in-the-wild exploitation, and EPSS assigns a 10.7% probability of exploitation in the next 30 days (96th percentile).
What to do: Apply Cisco's fixed IOS/IOS XE software releases per the vendor advisory, consistent with the CISA KEV required action; if patching must be deferred, restrict SNMP access to trusted management hosts with access control lists, disable SNMP where it is unused, and prefer SNMPv3 with strong, unique credentials. Audit whether SNMP is enabled and reachable from untrusted networks, and rotate default or widely shared community strings (e.g., 'public'), since only traffic directed to the device can trigger the flaw.
| Cisco IOS | Software releases with SNMP enabled (v1, v2c, or v3); specific affected/fixed release trains not provided in source data |
| Cisco IOS XE | Software releases with SNMP enabled (v1, v2c, or v3); specific affected/fixed release trains not provided in source data |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device. The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or earlier) or the user credentials (SNMPv3). An exploit could allow the attacker to execute arbitrary code and obtain full control of the system or to cause a reload of the affected system. Only traffic directed to the affected system can be used to exploit this vulnerability.
- Affected
- Cisco IOS and IOS XE Software
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- ios, ios xe
- Weakness
- CWE-119
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.