ZeroHour
Security Affairspublished ()ingested @securityaffairs

Cisco patched CVE-2017-3881 IOS XE Vulnerability leaked in CIA Vault 7 Dump

criticalVulnerabilityimportance 60CVE-2017-3881

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-3881
Unauthenticated RCE in Cisco IOS/IOS XE switches via malformed CMP Telnet options

CVE-2017-3881 is a critical (CVSS 9.8) unauthenticated remote code execution flaw, classified CWE-20, in the Cluster Management Protocol (CMP) processing code of Cisco IOS and IOS XE, which uses Telnet internally for signaling between switch cluster members. Because affected devices accept CMP-specific Telnet options on any inbound Telnet connection and mishandle malformed ones, an unauthenticated attacker who opens a Telnet session to a Telnet-enabled device and sends malformed CMP options can trigger the flaw. Successful exploitation lets the attacker execute arbitrary code with elevated privileges, gaining full control of the device, or force a reload of the switch. Affected hardware spans over 300 switching models per related coverage — Catalyst switches, Embedded Service 2020 and IE Industrial Ethernet switches, several EtherSwitch service modules, the ME 4924-10GE, RF Gateway 10, and the CGESM module for HP — running IOS or IOS XE with Telnet enabled; devices that accept only SSH are not remotely exploitable. The bug was disclosed via the March 2017 WikiLeaks Vault 7 CIA leak (tied to the 'Zero Disco' toolkit in related coverage), patched by Cisco that month, has a public PoC (Exploit-DB 41872), was added to CISA's KEV on 2022-03-25 (ransomware use unknown), and EPSS rates a 99% probability of exploitation in 30 days (100th percentile), so in-the-wild exploitation should be assumed.

Do: Upgrade affected switches to the fixed IOS/IOS XE releases listed in Cisco's advisory for bug CSCvd48893 (the CISA KEV required action is to apply the vendor updates). Until patched, disable Telnet on vty lines and use SSH, or restrict inbound TCP/23 to trusted management hosts, since the bug is only reachable via inbound Telnet sessions. Audit configurations for 'transport input telnet' and prioritize internet-facing or widely reachable Catalyst, IE industrial, and EtherSwitch-service-module devices.

9.899% KEV PoC
  • Cisco IOS (Catalyst switches, Embedded Service 2020 switches, Enhanced Layer 2 EtherSwitch Service Module, Enhanced Layer 2/3 Affected IOS releases on these switching platforms per Cisco's advisory (bug ID CSCvd48893); fixed releases published March 2017
  • Cisco IOS XE (same affected switching platforms) Affected IOS XE releases per Cisco's advisory (bug ID CSCvd48893); fixed releases published March 2017
mass≈1M+ deployed affected switches across 300+ models (only the Telnet-enabled subset is exploitable, likely hundreds of thousands of exposed systems)
Full article389 words · extracted from securityaffairs.com · click to collapse

Cisco patched the critical CVE-2017-3881 flaw that affects CISCO Catalyst switches and that can be potentially exploited by attackers to hijack networks.

Cisco patched a critical security flaw, tracked as CVE-2017-3881, affecting its CISCO Catalyst switches that can be potentially exploited by attackers to hijack networks.

The vulnerability was disclosed in the CIA Vault 7 data leak, according to Switchzilla a remote attacker can exploit it by simply establishing a Telnet connection and sending a cluster management protocol (CMP) command to the affected network device.

“The Cluster Management Protocol utilizes Telnet internally as a signaling and command protocol between cluster members. The vulnerability is due to the combination of two factors:

  • The failure to restrict the use of CMP-specific Telnet options only to internal, local communications between cluster members and instead accept and process such options over any Telnet connection to an affected device, and
  • The incorrect processing of malformed CMP-specific Telnet options.

” reads the Cisco security advisory published on Monday.

CVE-2017-3881 flaw CISCO Catalyst switches

The vulnerability affects the default configuration of the flawed devices even when the user doesn’t have switch clusters configured, and can be exploited over either IPv4 or IPv6.

“An attacker could exploit this vulnerability by sending malformed CMP-specific Telnet options while establishing a Telnet session with an affected Cisco device configured to accept Telnet connections,” 

Artem Kondratenko published the CVE-2017-3881 Cisco Catalyst RCE Proof-Of-Concept exploit code.

“Do you still have telnet enabled on your Catalyst switches? Think twice, here’s a proof-of-concept remote code execution exploit for Catalyst 2960 switch with latest suggested firmware. Check out the exploit code here.” wrote Kondratenko.”What follows is a detailed write-up of the exploit development process for the vulnerability leaked from CIA’s archive on March 7th 2017 and publicly disclosed by Cisco Systems on March 17th 2017. At the time of writing this post there is no patch available. Nonetheless there is a remediation – disable telnet and use SSH instead.”

Just after the disclosure of the CVE-2017-3881 flaw, CISCO confirmed that the IOS / IOS XE bug affects more than 300 of its switch models, including Cisco Catalyst, Embedded Services, and Industrial Ethernet switch models.

As mitigation measures, experts from CISCO suggested to disabled Telnet connections, SSH remains the best option to remotely access the devices.

[adrotate banner=”9″]

Pierluigi Paganini

(Security Affairs – CVE-2017-3881, Cisco Catalyst)

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/58969/hacking/cisco-cve-2017-3881-patched.html