cbcvebase.
CVE-2017-6739
published 2017-07-17

CVE-2017-6739: A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute…

PriorityP183high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
10.55%
95.3th percentile
A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device. The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or earlier) or the user credentials (SNMPv3). An exploit could allow the attacker to execute arbitrary code and obtain full control of the system or to cause a reload of the affected system. Only traffic directed to the affected system can be used to exploit this vulnerability.

Affected

5 ranges
VendorProductVersion rangeFixed in
ciscoios12.0 – 12.4
ciscoios15.0 – 15.6
ciscoios_and_ios_xe
ciscoios_xe2.2.0 – 3.17.0
intellishielduniversal_product

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector is a crafted SNMP packet sent via IPv4 or IPv6 directly to the affected Cisco IOS/IOS XE device; only traffic directed to the affected system can be used to exploit this vulnerability
  • All three SNMP versions (1, 2c, 3) are affected; monitor for anomalous SNMP traffic (UDP/161) to Cisco IOS/IOS XE devices from unexpected sources
  • For SNMPv2c/v1 exploitation, attacker must know the SNMP read-only community string; detect brute-force or unauthorized use of community strings against Cisco devices
  • For SNMPv3 exploitation, attacker must have valid user credentials; monitor for unexpected SNMPv3 authentication attempts or new SNMPv3 user activity on Cisco IOS/IOS XE devices
  • Successful exploitation may result in a device reload; unexpected Cisco IOS/IOS XE reloads should be investigated as potential exploitation indicators
  • Track Cisco bug IDs CSCsy56638, CSCve54313, and CSCve57697 for patch status and affected software versions when triaging exposed devices
  • ·The vulnerability is a buffer overflow in the SNMP subsystem (CWE-119); exploitation requires authentication — either a known SNMP read-only community string (v1/v2c) or valid SNMPv3 user credentials, limiting unauthenticated exploitation
  • ·Scope is limited to Cisco IOS and IOS XE Software only; only traffic directed to the affected system (not transit traffic) can be used to exploit these vulnerabilities

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
vendor_cisco8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.