Executive brief
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and IOS XE Software allows an unauthenticated, remote attacker to execute arbitrary code with elevated privileges or cause a device reload. The flaw exists because CMP-specific Telnet options are incorrectly processed and accepted over any Telnet connection rather than being restricted to internal cluster communications.
Affected products
- Cisco IOS
- Cisco IOS XE
- Cisco Catalyst switches
- Cisco Embedded Service 2020 switches
- Cisco Enhanced Layer 2 EtherSwitch Service Module
- Cisco Enhanced Layer 2/3 EtherSwitch Service Module
- Cisco Gigabit Ethernet Switch Module (CGESM) for HP
- Cisco IE Industrial Ethernet switches
- Cisco ME 4924-10GE switch
- Cisco RF Gateway 10
- Cisco SM-X Layer 2/3 EtherSwitch Service Module
Timeline
- 2017-03-17: advisory: Initial Cisco advisory published
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-25: disclosed