CVE-2017-6740
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.
Required action
Apply updates per vendor instructions.
CISA notes
https://nvd.nist.gov/vuln/detail/CVE-2017-6740
Description
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP - Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or earlier, the attacker must know the SNMP read-only community string for the affected system. To exploit these vulnerabilities via SNMP Version 3, the attacker must have user credentials for the affected system. A successful exploit could allow the attacker to execute arbitrary code and obtain full control of the affected system or cause the affected system to reload. Customers are advised to apply the workaround as contained in the Workarounds section below. Fixed software information is available via the Cisco IOS Software Checker. All devices that have enabled SNMP and have not explicitly excluded the affected MIBs or OIDs should be considered vulnerable. There are workarounds that address these vulnerabilities.
Severity
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAffected Products
| Vendor | Product | Affected versions |
|---|---|---|
| Cisco | IOS | 12.2(14)ZA 12.2(14)ZA3 12.2(14)ZA2 12.2(14)ZA5 12.2(14)ZA4 12.2(14)ZA6 12.2(14)ZA7 12.2(25)SE2 12.2(29)SV2 12.2(17d)SXB6 12.2(17d)SXB11 12.2(17d)SXB7 12.2(17d)SXB4 12.2(17d)SXB2 12.2(17d)SXB3 12.2(17d)SXB5 12.2(17d)SXB10 12.2(17d)SXB8 12.2(17d)SXB11a 12.2(17d)SXB1 12.2(17d)SXB9 12.2(18)SO1 12.2(18)SO3 12.2(18)SO2 12.2(18)SXF 12.2(18)SXF5 12.2(18)SXF6 12.2(18)SXF15 12.2(18)SXF10 12.2(18)SXF17b 12.2(18)SXF4 12.2(18)SXF15a 12.2(18)SXF3 12.2(18)SXF17 12.2(18)SXF12 12.2(18)SXF8 12.2(18)SXF10a 12.2(18)SXF16 12.2(18)SXF7 12.2(18)SXF17a 12.2(18)SXF14 12.2(18)SXF12a 12.2(18)SXF9 12.2(18)SXF13 12.2(18)SXF2 12.2(18)SXF11 12.2(28)ZX 12.2(33)STE0 15.0(1)XO1 15.0(1)XO 15.0(2)XO 15.0(2)SG11a 15.0(1)EX 15.0(2)EX2 15.0(2)EX8 15.0(2)EX10 15.0(2)EX11 15.0(2)EX13 15.0(2)EX12 15.1(2)SY9 15.1(3)MRA3 15.1(3)MRA4 15.1(3)SVB1 15.1(3)SVB2 15.1(3)SVD 15.1(3)SVD1 15.1(3)SVD2 15.1(3)SVF 15.1(3)SVF1 15.1(3)SVE 15.1(3)SVG 15.1(3)SVJ2 |
| IntelliShield | Universal Product | N/A |
References
4 LinksRecord Details
More from Cisco
Cisco HyperFlex HX Command Injection Vulnerabilities
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
Cisco HyperFlex HX Command Injection Vulnerabilities
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.