cbcvebase.
CVE-2017-6737
published 2017-07-17

CVE-2017-6737: A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute…

PriorityP185high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
42.63%
98.6th percentile
A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device. The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or earlier) or the user credentials (SNMPv3). An exploit could allow the attacker to execute arbitrary code and obtain full control of the system or to cause a reload of the affected system. Only traffic directed to the affected system can be used to exploit this vulnerability.

Affected

978 ranges· showing 25
VendorProductVersion rangeFixed in
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios

Detection & IOCsextracted from sources · hover to see the quote

portSNMP (UDP 161) via IPv4 or IPv6
  • Monitor for crafted SNMP packets (all versions: 1, 2c, 3) directed to Cisco IOS/IOS XE devices; exploitation requires a valid SNMP read-only community string (v1/v2c) or valid user credentials (v3).
  • Alert on unexpected Cisco IOS/IOS XE device reloads or crashes coinciding with inbound SNMP traffic, which may indicate exploitation of the buffer overflow in the SNMP subsystem.
  • Only traffic directed to the affected system (not transit traffic) can be used to exploit these vulnerabilities; filter/alert on direct SNMP traffic to network device management interfaces.
  • Track Cisco Bug IDs CSCsy56638, CSCve54313, and CSCve57697 for patch status on affected Cisco IOS and IOS XE devices.
  • ·CVE-2017-6737 affects Cisco IOS and IOS XE Software only; the sources also reference Juniper Junos OS CVE-2017-2345 which is explicitly noted as a DIFFERENT issue and should not be conflated.
  • ·The vulnerability is in the SNMP subsystem and is exploitable only by authenticated attackers (community string for v1/v2c, or credentials for v3); unauthenticated exploitation is not possible.
  • ·The root cause is a buffer overflow condition in the SNMP subsystem (CWE-119), affecting all SNMP versions (1, 2c, 3).

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
vendor_cisco8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.