CVE-2017-6739
published 2017-07-17CVE-2017-6739: A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute…
PriorityP183high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-03-24
Exploited in the wild
EPSS
10.55%
95.3th percentile
A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device.
The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or earlier) or the user credentials (SNMPv3). An exploit could allow the attacker to execute arbitrary code and obtain full control of the system or to cause a reload of the affected system.
Only traffic directed to the affected system can be used to exploit this vulnerability.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | 12.0 – 12.4 | — |
| cisco | ios | 15.0 – 15.6 | — |
| cisco | ios_and_ios_xe | — | — |
| cisco | ios_xe | 2.2.0 – 3.17.0 | — |
| intellishield | universal_product | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit vector is a crafted SNMP packet sent via IPv4 or IPv6 directly to the affected Cisco IOS/IOS XE device; only traffic directed to the affected system can be used to exploit this vulnerability ↗
- →All three SNMP versions (1, 2c, 3) are affected; monitor for anomalous SNMP traffic (UDP/161) to Cisco IOS/IOS XE devices from unexpected sources ↗
- →For SNMPv2c/v1 exploitation, attacker must know the SNMP read-only community string; detect brute-force or unauthorized use of community strings against Cisco devices ↗
- →For SNMPv3 exploitation, attacker must have valid user credentials; monitor for unexpected SNMPv3 authentication attempts or new SNMPv3 user activity on Cisco IOS/IOS XE devices ↗
- →Successful exploitation may result in a device reload; unexpected Cisco IOS/IOS XE reloads should be investigated as potential exploitation indicators ↗
- →Track Cisco bug IDs CSCsy56638, CSCve54313, and CSCve57697 for patch status and affected software versions when triaging exposed devices ↗
- ·The vulnerability is a buffer overflow in the SNMP subsystem (CWE-119); exploitation requires authentication — either a known SNMP read-only community string (v1/v2c) or valid SNMPv3 user credentials, limiting unauthenticated exploitation ↗
- ·Scope is limited to Cisco IOS and IOS XE Software only; only traffic directed to the affected system (not transit traffic) can be used to exploit these vulnerabilities ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
vendor_cisco8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
cisa·2022-03-03·CVSS 8.8
CVE-2017-6739 [HIGH] CWE-119 Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
Vulnerability: Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
Affected: Cisco IOS and IOS XE Software
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-6739
Remediation Due Date: 2022-03-24
CISA ICS
Rockwell Automation Allen-Bradley Stratix and ArmorStratix
cisa_ics·2017-08-28
Rockwell Automation Allen-Bradley Stratix and ArmorStratix
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Allen-Bradley Stratix and ArmorStratix
Last RevisedAugust 28, 2017
Alert CodeICSA-17-208-04
## CVSS v3 8.8
ATTENTION: Remotely exploitable/low skill level to exploit
Vendor: Rockwell Automation
Equipment: Allen-Bradley Stratix and ArmorStratix
Vulnerabilities: SNMP Remote Code Execution Vulnerabilities in Cisco IOS and IOS XE Software
## REPOSTED INFORMATION
This advisory was originally posted to the NCCIC Portal on July 27, 2017, and is being released to the NCCIC/ICS-CERT web site.
## AFFECTED PRODUCTS
The following versions of Allen-Bradley Stratix
Cisco
SNMP Remote Code Execution Vulnerabilities in Cisco IOS and IOS XE Software
vendor_cisco·2017-06-29·CVSS 8.8
CVE-2017-6736 [HIGH] CWE-119 SNMP Remote Code Execution Vulnerabilities in Cisco IOS and IOS XE Software
SNMP Remote Code Execution Vulnerabilities in Cisco IOS and IOS XE Software
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities.
The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP - Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or earlier, the at
Cisco
SNMP Remote Code Execution Vulnerabilities in Cisco IOS and IOS XE Software
vendor_cisco·CVSS 3.0
CVE-2017-6739 SNMP Remote Code Execution Vulnerabilities in Cisco IOS and IOS XE Software
CVE-2017-6739: SNMP Remote Code Execution Vulnerabilities in Cisco IOS and IOS XE Software
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP - Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or ea
GHSA
GHSA-p8jh-6v2f-m29j: The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 12
ghsa_unreviewed·2022-05-13
CVE-2017-6739 [HIGH] CWE-119 GHSA-p8jh-6v2f-m29j: The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 12
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 2.2 through 3.17 contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP: Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or earlier, the attacker must know the SNMP read-
VulnCheck
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
vulncheck·2017·CVSS 8.8
CVE-2017-6739 [HIGH] CWE-119 Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.
Affected: Cisco IOS and IOS XE Software
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-20170629-snmp.html
Remediation Due: 2022-03-24
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmphttp://www.securityfocus.com/bid/99345http://www.securitytracker.com/id/1038808https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmphttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6739
2017-07-17
Published
2022-03-03
Added to CISA KEV
Exploited in the wild