CISCO issues security patches for nine serious RCEs in SNMP subsystem in IOS and IOS XE
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-6736 | Buffer Overflow RCE in Cisco IOS and IOS XE SNMP Subsystem CVE-2017-6736 is one of nine buffer overflow vulnerabilities in the SNMP subsystem of Cisco IOS and IOS XE that affect all versions of SNMP (v1, 2c, and 3). An authenticated remote attacker triggers it by sending a crafted SNMP packet via IPv4 or IPv6 directly to an affected device, needing only the read-only community string for SNMPv2c or earlier, or valid SNMPv3 user credentials. A successful exploit yields arbitrary code execution with full control of the device, or forces the system to reload. Any IOS or IOS XE device with SNMP enabled that has not explicitly excluded the affected MIBs/OIDs should be considered vulnerable, including Cisco IOS-based networking gear and, per vendor notices, Rockwell industrial switches built on Cisco IOS. Exploitation is confirmed in the wild: the flaw is on CISA's KEV catalog (added 2022-03-03, with applying vendor updates as the required action), EPSS assigns a ~70.6% probability of exploitation within 30 days (99th percentile), and public proof-of-concept code is available. Do: Upgrade IOS/IOS XE to a fixed release identified via Cisco's IOS Software Checker, which is the required action under CISA KEV. As interim mitigation, restrict SNMP to trusted management hosts with ACLs, prefer SNMPv3 with strong credentials, and disable SNMP or exclude the affected MIBs/OIDs, since any device with SNMP enabled and the affected MIBs/OIDs not excluded is vulnerable. Also audit the network for configured SNMP community strings and internet-reachable devices accepting SNMP on IPv4 or IPv6. | 8.8 | 71% | KEV PoC ×2 |
| masshundreds of thousands of internet-exposed Cisco IOS/IOS XE devices with SNMP enabled (total installed base in the millions) | |
| CVE-2017-6744 | Authenticated SNMP Buffer Overflow RCE in Cisco IOS and IOS XE CVE-2017-6744 is a buffer overflow in the SNMP subsystem of Cisco IOS and IOS XE that lets an authenticated, remote attacker execute arbitrary code with full control of the device or force it to reload. Exploitation is triggered by sending a crafted SNMP packet directly to an affected system over IPv4 or IPv6; all SNMP versions (1, 2c, and 3) are affected, and the attacker must know the SNMP read-only community string (v1/2c) or hold valid user credentials (v3). Only traffic directed to the affected device can exploit the flaw, not transit traffic. Any IOS or IOS XE device with SNMP enabled that has not explicitly excluded the affected MIBs/OIDs should be considered vulnerable. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating known in-the-wild exploitation; no public proof-of-concept is known, and EPSS puts 30-day exploitation probability at 7.2% (94th percentile). Do: Inventory IOS/IOS XE devices for SNMP enabled with the affected MIBs/OIDs reachable, then upgrade to a fixed release identified with Cisco's IOS Software Checker per vendor instructions, as required by the CISA KEV listing. As an interim mitigation, restrict SNMP (all versions) to trusted management hosts with ACLs, exclude the affected MIBs/OIDs listed in the Cisco advisory, or disable SNMP if unused. Verify that community strings and SNMPv3 credentials are not exposed to untrusted networks, since both are prerequisites for exploitation. | 8.8 | 7% | KEV |
| massMillions of deployed Cisco IOS/IOS XE routers and switches worldwide, with likely hundreds of thousands of SNMP-enabled devices internet-exposed |
Full article568 words · extracted from securityaffairs.com · click to collapse

Cisco has fixed nine serious remote code execution flaws in the SNMP subsystem running in all the releases of IOS and IOS XE software.
The tech giant publicly disclosed the vulnerability on June 29 and provided workarounds, not it is notifying customers about the availability of security patches.
The nine issues, that have been tracked with codes from CVE-2017-6736 to CVE-2017-6744, were all patched by the company. All the flaws could be exploited by a remote unauthenticated attacker by sending specially crafted SNMP packets, resulting in arbitrary code execution or causing the system to reload.
“The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities.” states the advisory published by CISCO in June.
The experts warned of nine flaws affecting the Simple Network Management Protocol (SNMP) component of IOS and IOS XE software.
The flaws are due to a buffer overflow condition in the SNMP subsystem, all versions of SNMP – Versions 1, 2c, and 3 are affected.

As reported by the advisory, an authenticated attacker who knows the SNMP read-only community string of a target system could remotely execute code or cause the device to reload by sending a specially crafted SNMP packet via IPv4 or IPv6.
The attack is very dangerous because hackers could obtain full control of vulnerable devices and the worst news is that CISCO warned customers that attackers in the wild know about the vulnerabilities and can exploit them in any moment.
“A successful exploit could allow the attacker to execute arbitrary code and obtain full control of the affected system or cause the affected system to reload,” Cisco said in its advisory.
Cisco confirmed that any device configured with a list of particular management information base (MIBs) is also vulnerable. MIBs are databases associated with SNMP implementations and are used to manage devices in a communication network.
CISCO when disclosed the issued The company’s original workaround recommendation was to disable the affected MIBs.
Devices configured with any of the following MIBs are vulnerable:
- ADSL-LINE-MIB
- ALPS-MIB
- CISCO-ADSL-DMT-LINE-MIB
- CISCO-BSTUN-MIB
- CISCO-MAC-AUTH-BYPASS-MIB
- CISCO-SLB-EXT-MIB
- CISCO-VOICE-DNIS-MIB
- CISCO-VOICE-NUMBER-EXPANSION-MIB
- TN3270E-RT-MIB
“Some of the MIBs may not be present on all systems or versions but are enabled when present,” continued the Cisco advisory.
“Administrators may be accustomed to utilizing the show snmp mib command in privileged EXEC mode to display a list of enabled MIBs on a device,” Cisco said. “Not all of the MIBs will be displayed in the output of the show snmp mib command but may still be enabled.” Customers were advised to implement the entire exclude list.
CISCO customers need to apply the patches, the company also recommends network managers to regularly change community strings, which are used to restrict read/write access to SNMP data on a device running IOS or IOS XE.
“These community strings, as with all passwords, should be chosen carefully to ensure they are not trivial,” Cisco said. “They should also be changed at regular intervals and in accordance with network security policies.”
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(Security Affairs – Cisco IOS Software, hacking)
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/61024/security/cisco-security-patches-snmp.html