ZeroHour

CVE-2017-6739

KEVmass

Buffer Overflow in Cisco IOS/IOS XE SNMP Allows Authenticated RCE

CISA: Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

CVSS 3.1
8.8 high
EPSS
11%p96
Published
()
KEV added
AI analysis

CVE-2017-6739 is a buffer overflow (CWE-119) in the SNMP implementation of Cisco IOS and IOS XE that allows an authenticated, remote attacker to execute arbitrary code or cause a device reload. It is triggered by sending a crafted SNMP packet directed at the affected device, and the attacker must already know the SNMP read-only community string (v1/v2c) or valid SNMPv3 user credentials; the flaw affects all SNMP versions (1, 2c, and 3). Successful code execution gives the attacker full control of the router or switch, while a simpler exploit path causes a denial-of-service reload. Any organization running Cisco IOS or IOS XE with SNMP enabled is potentially affected, which given Cisco's dominance in enterprise networking represents a very large installed base. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), confirming in-the-wild exploitation, and EPSS assigns a 10.7% probability of exploitation in the next 30 days (96th percentile).

What to do: Apply Cisco's fixed IOS/IOS XE software releases per the vendor advisory, consistent with the CISA KEV required action; if patching must be deferred, restrict SNMP access to trusted management hosts with access control lists, disable SNMP where it is unused, and prefer SNMPv3 with strong, unique credentials. Audit whether SNMP is enabled and reachable from untrusted networks, and rotate default or widely shared community strings (e.g., 'public'), since only traffic directed to the device can trigger the flaw.

Affected
Cisco IOSSoftware releases with SNMP enabled (v1, v2c, or v3); specific affected/fixed release trains not provided in source data
Cisco IOS XESoftware releases with SNMP enabled (v1, v2c, or v3); specific affected/fixed release trains not provided in source data
Estimated exposure
mass≈ hundreds of thousands of internet-exposed Cisco IOS/IOS XE devices (total enterprise installed base in the millions) — Cisco IOS/IOS XE is the dominant enterprise router and switch platform and public internet scans (e.g., Shodan/Censys) consistently show on the order of hundreds of thousands of Cisco devices exposing management protocols such as SNMP,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device. The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or earlier) or the user credentials (SNMPv3). An exploit could allow the attacker to execute arbitrary code and obtain full control of the system or to cause a reload of the affected system. Only traffic directed to the affected system can be used to exploit this vulnerability.

CISA Known Exploited Vulnerability
Affected
Cisco IOS and IOS XE Software
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
ios, ios xe
Weakness
CWE-119
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.