CVE-2017-6742
KEVmassAuthenticated SNMP Remote Code Execution in Cisco IOS and IOS XE Software
CISA: Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
CVE-2017-6742 is a memory-corruption flaw (CWE-119) in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE. It is triggered when an affected device processes crafted SNMP packets sent by an authenticated, remote attacker, meaning the device must have SNMP enabled and the attacker must hold valid SNMP credentials or community strings. Successful exploitation lets the attacker execute code on the router or switch, or force the device to reload, yielding either full control of the device or a denial of service on critical network infrastructure. Any organization running vulnerable Cisco IOS or IOS XE releases with SNMP enabled on routers, switches, or other network devices is affected. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2023-04-19), confirming in-the-wild exploitation; EPSS estimates a 21.4% probability of exploitation within 30 days (97th percentile), and no public proof-of-concept code is known.
What to do: Upgrade affected Cisco IOS and IOS XE devices to fixed releases per Cisco's advisory, prioritizing internet-facing routers and switches as the KEV listing makes patching mandatory for federal agencies and urgent for others. As interim mitigation, restrict SNMP access to trusted management hosts with ACLs, disable SNMP entirely where it is not required, and rotate SNMP community strings/credentials that could be used for authentication. Inventory devices for enabled SNMP services and vulnerable releases, focusing first on edge and internet-exposed infrastructure.
| Cisco IOS | — |
| Cisco IOS XE Software | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device. The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or earlier) or the user credentials (SNMPv3). An exploit could allow the attacker to execute arbitrary code and obtain full control of the system or to cause a reload of the affected system. Only traffic directed to the affected system can be used to exploit this vulnerability.
- Affected
- Cisco IOS and IOS XE Software
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- ios, ios xe
- Weakness
- CWE-119
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H