cbcvebase.
CVE-2017-6741
published 2017-07-17

CVE-2017-6741: A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute…

PriorityP260high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
6.35%
92.9th percentile
A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device. The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or earlier) or the user credentials (SNMPv3). An exploit could allow the attacker to execute arbitrary code and obtain full control of the system or to cause a reload of the affected system. Only traffic directed to the affected system can be used to exploit this vulnerability.

Affected

202 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector is a crafted SNMP packet sent via IPv4 or IPv6 directly to the affected Cisco IOS/IOS XE device; only traffic directed to the affected system can be used to exploit this vulnerability
  • All three SNMP versions (1, 2c, 3) are affected; monitor for anomalous SNMP traffic on UDP/161 and UDP/162 to Cisco IOS/IOS XE devices
  • For SNMPv1/v2c exploitation, attacker must know the SNMP read-only community string; alert on SNMP requests using default or known community strings from untrusted sources
  • For SNMPv3 exploitation, attacker must have valid user credentials; monitor for SNMPv3 authentication attempts from unexpected sources
  • Successful exploitation results in arbitrary code execution or device reload; unexpected Cisco IOS/IOS XE reloads may indicate exploitation attempts
  • Track Cisco bug IDs CSCsy56638, CSCve54313, and CSCve57697 for patch status on affected Cisco IOS and IOS XE devices
  • ·The vulnerability is a buffer overflow in the SNMP subsystem; applies to Cisco IOS and IOS XE Software across all SNMP versions (1, 2c, 3)
  • ·Customers are advised to apply the workaround (disabling or restricting SNMP access via ACLs) as described in the Cisco Security Advisory

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.