cbcvebase.
CVE-2017-3881
published 2017-03-17

CVE-2017-3881: A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote…

PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-04-15
Exploited in the wild
EPSS
98.98%
99.9th percentile
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges. The Cluster Management Protocol utilizes Telnet internally as a signaling and command protocol between cluster members. The vulnerability is due to the combination of two factors: (1) the failure to restrict the use of CMP-specific Telnet options only to internal, local communications between cluster members and instead accept and process such options over any Telnet connection to an affected device; and (2) the incorrect processing of malformed CMP-specific Telnet options. An attacker could exploit this vulnerability by sending malformed CMP-specific Telnet options while establishing a Telnet session with an affected Cisco device configured to accept Telnet connections. An exploit could allow an attacker to execute arbitrary code and obtain full control of the device or cause a reload of the affected device. This affects Catalyst switches, Embedded Service 2020 switches, Enhanced Layer 2 EtherSwitch Service Module, Enhanced Layer 2/3 EtherSwitch Service Module, Gigabit Ethernet Switch Module (CGESM) for HP, IE Industrial Ethernet switches, ME 4924-10GE switch, RF Gateway 10, and SM-X Layer 2/3 EtherSwitch Service Module. Cisco Bug IDs: CSCvd48893.

Affected

3 ranges
VendorProductVersion rangeFixed in
ciscoios12.2s – 15.1\(3\)svs
ciscoios_and_ios_xe
ciscoios_xe3.2sg – 3.9e

Detection & IOCsextracted from sources · hover to see the quote

otherCiscoEMX-1 to CiscoEMX-5
otherEnaQWklg0
otherEnaQWklg1
otherEnaQWklg2
  • Exploit targets Telnet (TCP/23) by sending malformed CMP-specific Telnet options during session establishment; detect anomalous Telnet option negotiation sequences directed at Cisco IOS/IOS XE devices
  • The modified CVE-2017-3881 Telnet exploit was used to enable arbitrary memory read/write on Cisco switches; monitor for unexpected Telnet sessions to management interfaces on Cisco Catalyst/IOS devices
  • Hunt for hidden rogue local accounts matching the pattern dg[0-9]y[0-9][a-z]pk on Cisco device running configurations, as these are rootkit-created hidden accounts
  • Hunt for hidden EEM scripts named CiscoEMX-1 through CiscoEMX-5 in Cisco device configurations; these are concealed by the rootkit and will not appear in standard 'show running-config' output
  • Hunt for hidden ACLs named EnaQWklg0, EnaQWklg1, EnaQWklg2 in Cisco device configurations; these are concealed by the rootkit from standard running-config output
  • Monitor for UDP traffic directed to any IP on a Cisco switch on non-standard/unexpected ports; the rootkit UDP controller accepts packets on any port regardless of whether it is open
  • Alert on unexpected last running-config write timestamp resets on Cisco devices, which the rootkit uses to hide configuration changes
  • Metasploit auxiliary module ios_telnet_rocem.rb targets this vulnerability against Cisco Catalyst 2960 and 3750; detect exploitation attempts using this module via IDS signatures on Telnet traffic
  • ·The vulnerability only affects Cisco IOS/IOS XE devices that are configured to accept Telnet connections; devices with Telnet disabled are not exploitable via this vector
  • ·The in-the-wild exploitation of CVE-2017-3881 observed in Operation Zero Disco is a modified variant that enables memory read/write rather than the original RCE/DoS; detection rules tuned only for the original exploit behavior may miss this modified version
  • ·Rootkit hooks into IOSd memory result in fileless components that disappear after reboot, meaning post-reboot forensics may not reveal compromise; low-level firmware and ROM region investigation is required
  • ·Newer Cisco switch models with ASLR are more resistant but not immune; repeated exploitation attempts can still succeed
  • ·There is currently no universal automated tool that can reliably determine whether a Cisco switch has been successfully compromised by this operation

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_cisco9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.