ZeroHour

CVE-2017-6744

KEVmass

Authenticated SNMP Buffer Overflow RCE in Cisco IOS and IOS XE

CISA: Cisco IOS Software SNMP Remote Code Execution Vulnerability

CVSS 3.1
8.8 high
EPSS
7%p94
Published
()
KEV added
AI analysis

CVE-2017-6744 is a buffer overflow in the SNMP subsystem of Cisco IOS and IOS XE that lets an authenticated, remote attacker execute arbitrary code with full control of the device or force it to reload. Exploitation is triggered by sending a crafted SNMP packet directly to an affected system over IPv4 or IPv6; all SNMP versions (1, 2c, and 3) are affected, and the attacker must know the SNMP read-only community string (v1/2c) or hold valid user credentials (v3). Only traffic directed to the affected device can exploit the flaw, not transit traffic. Any IOS or IOS XE device with SNMP enabled that has not explicitly excluded the affected MIBs/OIDs should be considered vulnerable. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating known in-the-wild exploitation; no public proof-of-concept is known, and EPSS puts 30-day exploitation probability at 7.2% (94th percentile).

What to do: Inventory IOS/IOS XE devices for SNMP enabled with the affected MIBs/OIDs reachable, then upgrade to a fixed release identified with Cisco's IOS Software Checker per vendor instructions, as required by the CISA KEV listing. As an interim mitigation, restrict SNMP (all versions) to trusted management hosts with ACLs, exclude the affected MIBs/OIDs listed in the Cisco advisory, or disable SNMP if unused. Verify that community strings and SNMPv3 credentials are not exposed to untrusted networks, since both are prerequisites for exploitation.

Affected
Cisco IOSAll releases with the SNMP subsystem enabled and not explicitly excluding the affected MIBs/OIDs (SNMP v1, v2c, and v3); fixed releases are identified via the C
Cisco IOS XEAll releases with the SNMP subsystem enabled and not explicitly excluding the affected MIBs/OIDs (SNMP v1, v2c, and v3); fixed releases are identified via the C
Estimated exposure
massMillions of deployed Cisco IOS/IOS XE routers and switches worldwide, with likely hundreds of thousands of SNMP-enabled devices internet-exposed — Cisco IOS/IOS XE runs on a very large share of enterprise, ISP, and data-center network infrastructure, and public internet scans historically show hundreds of thousands of Cisco devices exposing SNMP to untrusted networks.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP - Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or earlier, the attacker must know the SNMP read-only community string for the affected system. To exploit these vulnerabilities via SNMP Version 3, the attacker must have user credentials for the affected system. A successful exploit could allow the attacker to execute arbitrary code and obtain full control of the affected system or cause the affected system to reload. Customers are advised to apply the workaround as contained in the Workarounds section below. Fixed software information is available via the Cisco IOS Software Checker. All devices that have enabled SNMP and have not explicitly excluded the affected MIBs or OIDs should be considered vulnerable. There are workarounds that address these vulnerabilities.

CISA Known Exploited Vulnerability
Affected
Cisco IOS software
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
ios
Weakness
CWE-119
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news