Junglewise Threat Intelligence

CVE-2017-6744: Cisco IOS Software SNMP Remote Code Execution Vulnerability

CVE-2017-6744 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-03-03

Technologies: Cisco IOS, Cisco Ios Software, Cisco IOS XE. Vendors: Cisco.

Executive brief

A buffer overflow vulnerability in the SNMP subsystem of Cisco IOS and IOS XE Software allows authenticated remote attackers to execute arbitrary code or cause a device reload. Exploitation requires sending crafted SNMP packets via IPv4 or IPv6 using valid community strings (v1/v2c) or user credentials (v3).

Affected products

  • Cisco IOS All versions of SNMP (1, 2c, 3) enabled
  • Cisco IOS XE All versions of SNMP (1, 2c, 3) enabled

Timeline

  • 2017-06-29: disclosed: Initial Cisco advisory publication
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats