CVE-2017-6742
published 2017-07-17CVE-2017-6742: A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute…
PriorityP185high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2023-05-10
Exploited in the wild
EPSS
21.42%
97.3th percentile
A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device.
The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or earlier) or the user credentials (SNMPv3). An exploit could allow the attacker to execute arbitrary code and obtain full control of the system or to cause a reload of the affected system.
Only traffic directed to the affected system can be used to exploit this vulnerability.
Affected
97 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
| cisco | cisco_ios_xe_software | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for crafted SNMP packets (v1, v2c, v3) directed at Cisco IOS/IOS XE devices; exploitation requires knowledge of the SNMP read-only community string (v1/v2c) or valid user credentials (v3). ↗
- →Alert on unexpected device reloads or process crashes in Cisco IOS/IOS XE SNMP subsystem, which may indicate a buffer overflow exploitation attempt (CVE-2017-6742, CWE-119). ↗
- →Only traffic directed to the affected system can trigger exploitation; filter and alert on inbound SNMP traffic from untrusted/external sources to Cisco IOS/IOS XE devices. ↗
- →Track Cisco bug IDs CSCsy56638, CSCve54313, and CSCve57697 when correlating vendor advisories and patch status for CVE-2017-6742 affected systems. ↗
- →Post-compromise, watch for creation of GRE tunnels, DNS hijacking, hidden configurations, and ACL bypass behaviors on Cisco routers as follow-on indicators after SNMP exploitation. ↗
- ·Exploitation requires authentication: attacker must possess the SNMP read-only community string (v1/v2c) or valid SNMPv3 user credentials; unauthenticated exploitation is not possible. ↗
- ·SNMPv1 and v2c transmit community strings in cleartext, making them subject to interception even if strong strings are chosen; SNMPv3 with encryption is strongly preferred. ↗
- ·The vulnerability affects all three SNMP versions (1, 2c, and 3) in Cisco IOS and IOS XE; disabling SNMP entirely or restricting via ACL is the recommended workaround per the vendor advisory. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
vendor_cisco8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
cisa·2023-04-19·CVSS 8.8
CVE-2017-6742 [HIGH] CWE-119 Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
Vulnerability: Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
Affected: Cisco IOS and IOS XE Software
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.
Required Action: Apply updates per vendor instructions.
Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmp; https://nvd.nist.gov/vuln/detail/CVE-2017-6742
Remediation Due Date: 2023-05-10
CISA ICS
Rockwell Automation Allen-Bradley Stratix and ArmorStratix
cisa_ics·2017-08-28
Rockwell Automation Allen-Bradley Stratix and ArmorStratix
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Allen-Bradley Stratix and ArmorStratix
Last RevisedAugust 28, 2017
Alert CodeICSA-17-208-04
## CVSS v3 8.8
ATTENTION: Remotely exploitable/low skill level to exploit
Vendor: Rockwell Automation
Equipment: Allen-Bradley Stratix and ArmorStratix
Vulnerabilities: SNMP Remote Code Execution Vulnerabilities in Cisco IOS and IOS XE Software
## REPOSTED INFORMATION
This advisory was originally posted to the NCCIC Portal on July 27, 2017, and is being released to the NCCIC/ICS-CERT web site.
## AFFECTED PRODUCTS
The following versions of Allen-Bradley Stratix
Cisco
SNMP Remote Code Execution Vulnerabilities in Cisco IOS and IOS XE Software
vendor_cisco·2017-06-29·CVSS 8.8
CVE-2017-6736 [HIGH] CWE-119 SNMP Remote Code Execution Vulnerabilities in Cisco IOS and IOS XE Software
SNMP Remote Code Execution Vulnerabilities in Cisco IOS and IOS XE Software
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities.
The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP - Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or earlier, the at
Cisco
SNMP Remote Code Execution Vulnerabilities in Cisco IOS and IOS XE Software
vendor_cisco·CVSS 3.0
CVE-2017-6742 SNMP Remote Code Execution Vulnerabilities in Cisco IOS and IOS XE Software
CVE-2017-6742: SNMP Remote Code Execution Vulnerabilities in Cisco IOS and IOS XE Software
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP - Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or ea
GHSA
GHSA-cw5p-gwrw-rv56: The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 12
ghsa_unreviewed·2022-05-13
CVE-2017-6742 [HIGH] CWE-119 GHSA-cw5p-gwrw-rv56: The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 12
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 2.2 through 3.17 contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP: Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or earlier, the attacker must know the SNMP read-
VulnCheck
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
vulncheck·2017·CVSS 8.8
CVE-2017-6742 [HIGH] CWE-119 Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.
Affected: Cisco IOS and IOS XE Software
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-20170629-snmp.html; https://cisa.gov/news-events/cybersecurity-advisories/aa23-108; https://www.ncsc.gov.uk/news/apt28-exploits-known-vulnerability-to-carry-out-reconnaissance-and-deploy-malware-on-cisco-routers; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://
No detection rules found.
No public exploits indexed.
Talos
State-sponsored campaigns target global network infrastructure
blogs_talos·2023-04-18
State-sponsored campaigns target global network infrastructure
Cisco is deeply concerned by an increase in the rate of high-sophistication attacks on network infrastructure — that we have observed and have seen corroborated by numerous reports issued by various intelligence organizations — indicating state-sponsored actors are targeting routers and firewalls globally. We have spoken about infrastructure security for a long time. However, while working with network infrastructure in various parts of the world, we have observed both espionage and obvious targeting to support future destructive attacks. While working with our partners, we have experienced the operational barriers that slow and sometimes stop security teams from properly securing network infrastructure. In this report, we are sharing both our observations of top-tier attackers and their a
Talos
State-sponsored campaigns target global network infrastructure
blogs_talos·2023-04-18
State-sponsored campaigns target global network infrastructure
## State-sponsored campaigns target global network infrastructure
Cisco is deeply concerned by an increase in the rate of high-sophistication attacks on network infrastructure — that we have observed and have seen corroborated by numerous reports issued by various intelligence organizations — indicating state-sponsored actors are targeting routers and firewalls globally. We have spoken about infrastructure security for a long time. However, while working with network infrastructure in various parts of the world, we have observed both espionage and obvious targeting to support future destructive attacks. While working with our partners, we have experienced the operational barriers that slow and sometimes stop security teams from properly securing network infrastructure. In this report, we
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmphttp://www.securityfocus.com/bid/99345http://www.securitytracker.com/id/1038808https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmphttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6742
2017-07-17
Published
2023-04-19
Added to CISA KEV
Exploited in the wild