cbcvebase.
CVE-2017-6742
published 2017-07-17

CVE-2017-6742: A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute…

PriorityP185high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2023-05-10
Exploited in the wild
EPSS
21.42%
97.3th percentile
A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device. The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or earlier) or the user credentials (SNMPv3). An exploit could allow the attacker to execute arbitrary code and obtain full control of the system or to cause a reload of the affected system. Only traffic directed to the affected system can be used to exploit this vulnerability.

Affected

97 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software
ciscocisco_ios_xe_software

Detection & IOCsextracted from sources · hover to see the quote

portSNMP (UDP 161) via IPv4 or IPv6
  • Monitor for crafted SNMP packets (v1, v2c, v3) directed at Cisco IOS/IOS XE devices; exploitation requires knowledge of the SNMP read-only community string (v1/v2c) or valid user credentials (v3).
  • Alert on unexpected device reloads or process crashes in Cisco IOS/IOS XE SNMP subsystem, which may indicate a buffer overflow exploitation attempt (CVE-2017-6742, CWE-119).
  • Only traffic directed to the affected system can trigger exploitation; filter and alert on inbound SNMP traffic from untrusted/external sources to Cisco IOS/IOS XE devices.
  • Track Cisco bug IDs CSCsy56638, CSCve54313, and CSCve57697 when correlating vendor advisories and patch status for CVE-2017-6742 affected systems.
  • Post-compromise, watch for creation of GRE tunnels, DNS hijacking, hidden configurations, and ACL bypass behaviors on Cisco routers as follow-on indicators after SNMP exploitation.
  • ·Exploitation requires authentication: attacker must possess the SNMP read-only community string (v1/v2c) or valid SNMPv3 user credentials; unauthenticated exploitation is not possible.
  • ·SNMPv1 and v2c transmit community strings in cleartext, making them subject to interception even if strong strings are chosen; SNMPv3 with encryption is strongly preferred.
  • ·The vulnerability affects all three SNMP versions (1, 2c, and 3) in Cisco IOS and IOS XE; disabling SNMP entirely or restricting via ACL is the recommended workaround per the vendor advisory.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
vendor_cisco8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.