Executive brief
A buffer overflow vulnerability in the SNMP subsystem of Cisco IOS and IOS XE Software allows an authenticated, remote attacker to execute arbitrary code or cause a device reload. The flaw can be exploited by sending crafted SNMP packets (v1, v2c, or v3) to an affected system, provided the attacker has valid community strings or user credentials.
Affected products
- Cisco IOS 12.0 through 12.4, 15.0 through 15.6
- Cisco IOS XE 2.2 through 3.17
Timeline
- 2017-06-29: disclosed: Initial Cisco advisory publication
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog