CVE-2017-6742

Confirmed PUBLISHED

A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely...

Cisco, IntelliShield · Cisco IOS XE Software, Universal Product
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
8.8 High

At a Glance

A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device.  The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or earlier) or the user credentials (SNMPv3). An exploit could allow the attacker to execute arbitrary code and obtain full control of the system or to cause a reload of the affected system. Only traffic directed to the affected system can be used to exploit this vulnerability.

edge nessus_scanner ios cisa
CVE Published
Jul 17, 2017
Exploitation Reported
Apr 19, 2023
CVSS
8.8 High
EPSS
Remote Low complexity No user interaction

Affected Versions

93 version rows · page 2 of 4

Vendor Product Version Status
Cisco
Cisco IOS XE Software

3.12.2S

Affected
Cisco
Cisco IOS XE Software

3.12.3S

Affected
Cisco
Cisco IOS XE Software

3.12.0aS

Affected
Cisco
Cisco IOS XE Software

3.12.4S

Affected
Cisco
Cisco IOS XE Software

3.13.0S

Affected
Cisco
Cisco IOS XE Software

3.13.1S

Affected
Cisco
Cisco IOS XE Software

3.13.2S

Affected
Cisco
Cisco IOS XE Software

3.13.3S

Affected
Cisco
Cisco IOS XE Software

3.13.4S

Affected
Cisco
Cisco IOS XE Software

3.13.5S

Affected
Cisco
Cisco IOS XE Software

3.13.2aS

Affected
Cisco
Cisco IOS XE Software

3.13.0aS

Affected
Cisco
Cisco IOS XE Software

3.13.5aS

Affected
Cisco
Cisco IOS XE Software

3.13.6S

Affected
Cisco
Cisco IOS XE Software

3.13.7S

Affected
Cisco
Cisco IOS XE Software

3.13.6aS

Affected
Cisco
Cisco IOS XE Software

3.13.7aS

Affected
Cisco
Cisco IOS XE Software

3.6.3E

Affected
Cisco
Cisco IOS XE Software

3.6.6E

Affected
Cisco
Cisco IOS XE Software

3.6.5bE

Affected
Cisco
Cisco IOS XE Software

3.14.0S

Affected
Cisco
Cisco IOS XE Software

3.14.1S

Affected
Cisco
Cisco IOS XE Software

3.14.2S

Affected
Cisco
Cisco IOS XE Software

3.14.3S

Affected
Cisco
Cisco IOS XE Software

3.14.4S

Affected

CVE References

  • cisco-sa-20170629-snmp sec.cloudapps.cisco.com · CVE Record https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurity...

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.