CVE-2017-6738
Confirmed PUBLISHEDThe Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an...
Recommended Action
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
At a Glance
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP - Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or earlier, the attacker must know the SNMP read-only community string for the affected system. To exploit these vulnerabilities via SNMP Version 3, the attacker must have user credentials for the affected system. A successful exploit could allow the attacker to execute arbitrary code and obtain full control of the affected system or cause the affected system to reload. Customers are advised to apply the workaround as contained in the Workarounds section below. Fixed software information is available via the Cisco IOS Software Checker. All devices that have enabled SNMP and have not explicitly excluded the affected MIBs or OIDs should be considered vulnerable. There are workarounds that address these vulnerabilities.
- CVE Published
- Jul 17, 2017
- Exploitation Reported
- Mar 03, 2022
- CVSS
- 8.8 High
- EPSS
- —
Affected Versions
428 version rows · page 7 of 18
| Vendor | Product | Version | Status |
|---|---|---|---|
| Cisco |
IOS
|
15.2(4)M1 |
Affected |
| Cisco |
IOS
|
15.2(4)M2 |
Affected |
| Cisco |
IOS
|
15.2(4)M4 |
Affected |
| Cisco |
IOS
|
15.2(4)M3 |
Affected |
| Cisco |
IOS
|
15.2(4)M5 |
Affected |
| Cisco |
IOS
|
15.2(4)M8 |
Affected |
| Cisco |
IOS
|
15.2(4)M10 |
Affected |
| Cisco |
IOS
|
15.2(4)M7 |
Affected |
| Cisco |
IOS
|
15.2(4)M6 |
Affected |
| Cisco |
IOS
|
15.2(4)M9 |
Affected |
| Cisco |
IOS
|
15.2(4)M6a |
Affected |
| Cisco |
IOS
|
15.2(4)M11 |
Affected |
| Cisco |
IOS
|
15.0(2)SG |
Affected |
| Cisco |
IOS
|
15.0(2)SG1 |
Affected |
| Cisco |
IOS
|
15.0(2)SG2 |
Affected |
| Cisco |
IOS
|
15.0(2)SG3 |
Affected |
| Cisco |
IOS
|
15.0(2)SG4 |
Affected |
| Cisco |
IOS
|
15.0(2)SG5 |
Affected |
| Cisco |
IOS
|
15.0(2)SG6 |
Affected |
| Cisco |
IOS
|
15.0(2)SG7 |
Affected |
| Cisco |
IOS
|
15.0(2)SG8 |
Affected |
| Cisco |
IOS
|
15.0(2)SG9 |
Affected |
| Cisco |
IOS
|
15.0(2)SG10 |
Affected |
| Cisco |
IOS
|
15.0(2)SG11 |
Affected |
| Cisco |
IOS
|
15.0(2)SG11a |
Affected |
CVE References
- cisco-sa-20170629-snmp sec.cloudapps.cisco.com · CVE Record https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurity...
Recommended Actions
- Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
- Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.
Known Exploited Vulnerability Sources
Catalogues that list this CVE as a known exploited vulnerability.
Per-source evidence links for KEV attestations are available through the KEVIntel Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| CISA First | 2022-03-03 00:00 UTC |
No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Virtual Patch
Compensating WAF rules to help reduce exposure to this CVE. Rule content and deployable vendor exports are available with KEVIntel Enterprise.
KEVIntel does not currently have a virtual patch for this CVE. When available, KEVIntel virtual patches ship as deployable ModSecurity, Cloudflare, and AWS WAF rules.
Enterprise feature. Virtual patch rule content and deployable vendor exports (ModSecurity, Cloudflare, AWS WAF) are available to KEVIntel Enterprise users.
CVSS Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
Exploited in the wild
Recorded 2022-03-03 00:00:00 UTC · CISA
Weaknesses (CWE)
-
Improper Restriction of Operations within the Bounds of a Memory Buffer
Timeline
Key exploitation, disclosure, scanner coverage, and KEV attestation events for this CVE.
-
00:00 UTC over 4 years ago00:00 UTC · over 4 years ago
Added to CISA KEV
Listed in the CISA Known Exploited Vulnerabilities catalog
-
21:00 UTC about 9 years ago21:00 UTC · about 9 years ago
CVE published
Vulnerability disclosed publicly
-
00:00 UTC over 9 years ago00:00 UTC · over 9 years ago
CVE ID reserved
Identifier reserved by the CNA
Automate This Intelligence with the Pro API
Confidence scoring, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
Pro API Example
GET /api/v2/pro/kevs/CVE-2017-6738
{
"cve_id": "CVE-2017-6738",
"title": "The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS ...",
"affected_vendor": "Cisco",
"affected_product": "IOS, Cisco IOS XE Software",
"affected_versions": [
{ "vendor": "...", "product": "...", "status": "affected", "display_label": "..." }
],
"confidence": "Confirmed",
"cvss_score": 8.8,
"epss_score": null,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "...": "Pro API fields" },
"proof_of_concepts": [ "..." ],
"scanner_integrations": [ "..." ]
}