← Vulnerability feed

Vulnerability record · CVE-2017-3881 · published 17 March 2017

CVE-2017-3881: Cisco IOS/IOS XE CMP Telnet Option Handling RCE

Cisco · Ios

Cisco IOS and IOS XE fail to restrict CMP-specific Telnet options to internal cluster communications and mishandle malformed CMP Telnet options, so any Telnet connection to an affected device can trigger the flaw. An unauthenticated remote attacker can cause a reload or execute code with elevated privileges, giving full control of the device.

9.8 CVSS 3.1 Critical CISA KEV since 25 Mar 2022 EPSS 99% · top 0.1% CWE-20 · Improper input validation
9.8CVSS 3.1 base score, v2 10.0
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
13References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges. The Cluster Management Protocol utilizes Telnet internally as a signaling and command protocol between cluster members. The vulnerability is due to the combination of two factors: (1) the failure to restrict the use of CMP-specific Telnet options only to internal, local communications between cluster members and instead accept and process such options over any Telnet connection to an affected device; and (2) the incorrect processing of malformed CMP-specific Telnet options. An attacker could exploit this vulnerability by sending malformed CMP-specific Telnet options while establishing a Telnet session with an affected Cisco device configured to accept Telnet connections. An exploit could allow an attacker to execute arbitrary code and obtain full control of the device or cause a reload of the affected device. This affects Catalyst switches, Embedded Service 2020 switches, Enhanced Layer 2 EtherSwitch Service Module, Enhanced Layer 2/3 EtherSwitch Service Module, Gigabit Ethernet Switch Module (CGESM) for HP, IE Industrial Ethernet switches, ME 4924-10GE switch, RF Gateway 10, and SM-X Layer 2/3 EtherSwitch Service Module. Cisco Bug IDs: CSCvd48893.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, unauthenticated remote code execution, KEV listing, near-maximum EPSS, and public exploit code make this an urgent patching priority.

What it is

Cisco IOS and IOS XE fail to restrict CMP-specific Telnet options to internal cluster communications and mishandle malformed CMP Telnet options, so any Telnet connection to an affected device can trigger the flaw. An unauthenticated remote attacker can cause a reload or execute code with elevated privileges, giving full control of the device.

Impact

An attacker gains arbitrary code execution with elevated privileges on the switch or router, or can force a reload, disrupting network operations.

Attack surface

Reached over the network via a Telnet session to a device configured to accept Telnet connections; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

CVE-2017-3881 is listed in CISA KEV with a 2022-03-25 addition date, has an EPSS 30-day probability of 0.98975 (99.9th percentile), and public exploit code is referenced on Exploit-DB, indicating active exploitation.

What to do

  • Apply the Cisco vendor advisory updates (cisco-sa-20170317-cmp) to affected IOS and IOS XE devices.
  • Disable Telnet and use SSH for management access where feasible.
  • Restrict management-plane access to trusted networks with ACLs or infrastructure ACLs.
  • Monitor for and block CMP-specific Telnet option negotiation on untrusted interfaces.
  • Track CISA KEV remediation due date (2022-04-15) and verify all affected Catalyst, IE, ME, RF Gateway, and EtherSwitch modules are patched.

Detection

  • Inspect Telnet session traffic for CMP-specific option negotiation or malformed option bytes.
  • Alert on unexpected device reloads or crash/restart events on IOS/IOS XE switches.
  • Monitor management-plane logs for Telnet connections from untrusted source addresses.
  • Use IDS/IPS signatures for CVE-2017-3881 exploit attempts against Telnet services.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-3881 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Cisco IOS and IOS XE Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-3881 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2023-20198Cisco IOS XE Web UI unauthenticated privilege escalation and implant deploymentCVE-2023-20198 is a critical flaw in the Cisco IOS XE web UI that lets an unauthenticated remote attacker gain initial access and create a local priv…KEVEPSS 100%analysed9.8CVE-2018-0171Cisco IOS Smart Install improper input validation allows remote code executionCisco IOS and IOS XE Smart Install fails to properly validate packet data, so a crafted Smart Install message sent to TCP port 4786 can overflow a bu…KEVEPSS 99%analysed9.8CVE-2018-0151Cisco IOS/IOS XE QoS UDP Port 18999 Buffer OverflowCisco IOS and IOS XE contain a buffer overflow in the QoS subsystem caused by incorrect bounds checking of values in packets sent to UDP port 18999. …KEVEPSS 14%analysed9.8CVE-2017-12240Cisco IOS and IOS XE DHCP Relay Buffer Overflow RCEThe DHCP relay subsystem in Cisco IOS 12.2 through 15.6 and Cisco IOS XE contains a buffer overflow caused by improper input validation of DHCPv4 pac…KEVEPSS 14%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.8CVE-2017-6736Cisco IOS and IOS XE SNMP buffer overflow remote code executionThe SNMP subsystem in Cisco IOS and IOS XE contains a buffer overflow that can be triggered by a crafted SNMP packet sent over IPv4 or IPv6. It affec…KEVEPSS 70%analysed8.8CVE-2017-6737Cisco IOS and IOS XE SNMP Buffer Overflow RCECisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMPv1, v2c, and v3. An authenticated remote attacker who know…KEVEPSS 45%analysed8.8CVE-2017-6738Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionThe SNMP subsystem in Cisco IOS and IOS XE Software contains a buffer overflow that affects SNMP versions 1, 2c, and 3. An authenticated remote attac…KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-2017-3881), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.