Cisco IOS vulnerabilities open Rockwell Industrial Switches to attacks
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-6736 | Buffer Overflow RCE in Cisco IOS and IOS XE SNMP Subsystem CVE-2017-6736 is one of nine buffer overflow vulnerabilities in the SNMP subsystem of Cisco IOS and IOS XE that affect all versions of SNMP (v1, 2c, and 3). An authenticated remote attacker triggers it by sending a crafted SNMP packet via IPv4 or IPv6 directly to an affected device, needing only the read-only community string for SNMPv2c or earlier, or valid SNMPv3 user credentials. A successful exploit yields arbitrary code execution with full control of the device, or forces the system to reload. Any IOS or IOS XE device with SNMP enabled that has not explicitly excluded the affected MIBs/OIDs should be considered vulnerable, including Cisco IOS-based networking gear and, per vendor notices, Rockwell industrial switches built on Cisco IOS. Exploitation is confirmed in the wild: the flaw is on CISA's KEV catalog (added 2022-03-03, with applying vendor updates as the required action), EPSS assigns a ~70.6% probability of exploitation within 30 days (99th percentile), and public proof-of-concept code is available. Do: Upgrade IOS/IOS XE to a fixed release identified via Cisco's IOS Software Checker, which is the required action under CISA KEV. As interim mitigation, restrict SNMP to trusted management hosts with ACLs, prefer SNMPv3 with strong credentials, and disable SNMP or exclude the affected MIBs/OIDs, since any device with SNMP enabled and the affected MIBs/OIDs not excluded is vulnerable. Also audit the network for configured SNMP community strings and internet-reachable devices accepting SNMP on IPv4 or IPv6. | 8.8 | 71% | KEV PoC ×2 |
| masshundreds of thousands of internet-exposed Cisco IOS/IOS XE devices with SNMP enabled (total installed base in the millions) | |
| CVE-2017-6744 | Authenticated SNMP Buffer Overflow RCE in Cisco IOS and IOS XE CVE-2017-6744 is a buffer overflow in the SNMP subsystem of Cisco IOS and IOS XE that lets an authenticated, remote attacker execute arbitrary code with full control of the device or force it to reload. Exploitation is triggered by sending a crafted SNMP packet directly to an affected system over IPv4 or IPv6; all SNMP versions (1, 2c, and 3) are affected, and the attacker must know the SNMP read-only community string (v1/2c) or hold valid user credentials (v3). Only traffic directed to the affected device can exploit the flaw, not transit traffic. Any IOS or IOS XE device with SNMP enabled that has not explicitly excluded the affected MIBs/OIDs should be considered vulnerable. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating known in-the-wild exploitation; no public proof-of-concept is known, and EPSS puts 30-day exploitation probability at 7.2% (94th percentile). Do: Inventory IOS/IOS XE devices for SNMP enabled with the affected MIBs/OIDs reachable, then upgrade to a fixed release identified with Cisco's IOS Software Checker per vendor instructions, as required by the CISA KEV listing. As an interim mitigation, restrict SNMP (all versions) to trusted management hosts with ACLs, exclude the affected MIBs/OIDs listed in the Cisco advisory, or disable SNMP if unused. Verify that community strings and SNMPv3 credentials are not exposed to untrusted networks, since both are prerequisites for exploitation. | 8.8 | 7% | KEV |
| massMillions of deployed Cisco IOS/IOS XE routers and switches worldwide, with likely hundreds of thousands of SNMP-enabled devices internet-exposed |
Full article640 words · extracted from securityaffairs.com · click to collapse

Vulnerabilities in Cisco IOS expose Rockwell Allen-Bradley Stratix and ArmorStratix industrial Ethernet switches to remote attacks.
Some models of the Allen-Bradley Stratix and ArmorStratix industrial Ethernet switches are exposed to remote attacks due to security flaws in Cisco’s IOS software.
According to the security alert issued by ICS-CERT, an authenticated remote attacker can exploit the flaws to execute code on an affected system or to trigger a DoS condition and consequent reload of the device.
“Successful exploitation of these vulnerabilities could allow an authenticated, remote attacker to execute code on an affected system or cause an affected system to crash and reload.” states the ICS-CERT.
Critical Infrastructure of any sectors worldwide is impacted, including Critical Manufacturing, Energy, and Water and Wastewater Systems.
Critical infrastructure relies on Cisco’s IOS software for secure integration with enterprise networks, this implies that Cisco IOS flaws can also affect Rockwell Automation products.
Rockwell Automation promptly informed customers of the high severity vulnerabilities in Cisco IOS and IOS XE. Nine flaws affect the versions 1, 2c and 3 of Simple Network Management Protocol (SNMP) subsystem.
The tech giant publicly disclosed the vulnerability on June 29 and provided workarounds, not it is notifying customers about the availability of security patches.
The nine issues, that have been tracked with codes from CVE-2017-6736 to CVE-2017-6744, were all patched by the company. All the flaws could be exploited by a remote unauthenticated attacker by sending specially crafted SNMP packets, resulting in arbitrary code execution or causing the system to reload.
“The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities.” states the advisory published by CISCO in June.
As reported by the advisory, an authenticated attacker who knows the SNMP read-only community string of a target system could remotely execute code or cause the device to reload by sending a specially crafted SNMP packet via IPv4 or IPv6.

The attack is very dangerous because hackers could obtain full control of vulnerable devices and the worst news is that CISCO warned customers that attackers in the wild know about the vulnerabilities and can exploit them in any moment.
“A successful exploit could allow the attacker to execute arbitrary code and obtain full control of the affected system or cause the affected system to reload,” Cisco said in its advisory.
The security holes can be exploited by sending a specially crafted SNMP packet via IPv4 or IPv6.
“To exploit these vulnerabilities via SNMP Version 2c or earlier, the attacker must know the SNMP read-only community string for the affected system. To exploit these vulnerabilities via SNMP Version 3, the attacker must have user credentials for the affected system,” Cisco said in its advisory.
Cisco found no evidence of cyber attack leveraging the flaws, but it confirmed people outside the company also was aware of their existence.
The flaws affect Allen-Bradley Stratix 5400, 5410, 5700 and 8000 models running version 15.2(5)EA.fc4 and earlier of the firmware, Stratix 5900 version 15.6(3)M1 and earlier, Stratix 8300 version 15.2(4)EA and earlier, and ArmorStratix 5700 version 15.2(5)EA.fc4 and earlier.
The vulnerabilities have been fixed in version 15.2(4a)EA5 for Stratix 8300 devices.
Waiting for security updates, Rockwell urges customers to disable specific management information bases (MIBs), use strong SNMP credentials, prevent unauthorized SNMP requests with firewall and other security appliances.
Rockwell customers can use Snort rules provided by Cisco to detect exploits.
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(Security Affairs – Cisco IOS Software, Rockwell Industrial Switches )
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/62347/breaking-news/cisco-ios-flaws-rockwell.html