Vulnerability record · CVE-2017-6736 · published 17 July 2017
CVE-2017-6736: Cisco IOS and IOS XE SNMP buffer overflow remote code execution
Cisco · Ios
The SNMP subsystem in Cisco IOS and IOS XE contains a buffer overflow that can be triggered by a crafted SNMP packet sent over IPv4 or IPv6. It affects SNMP versions 1, 2c and 3, and a successful exploit can execute arbitrary code or reload the device. Because SNMP is widely enabled on network gear, this is a serious risk to core routing and switching infrastructure.
Description
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP - Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or earlier, the attacker must know the SNMP read-only community string for the affected system. To exploit these vulnerabilities via SNMP Version 3, the attacker must have user credentials for the affected system. A successful exploit could allow the attacker to execute arbitrary code and obtain full control of the affected system or cause the affected system to reload. Customers are advised to apply the workaround as contained in the Workarounds section below. Fixed software information is available via the Cisco IOS Software Checker. All devices that have enabled SNMP and have not explicitly excluded the affected MIBs or OIDs should be considered vulnerable. There are workarounds that address these vulnerabilities.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityRemote pre-auth-adjacent code execution on core network devices, active in CISA KEV with public exploits and very high EPSS.
What it is
The SNMP subsystem in Cisco IOS and IOS XE contains a buffer overflow that can be triggered by a crafted SNMP packet sent over IPv4 or IPv6. It affects SNMP versions 1, 2c and 3, and a successful exploit can execute arbitrary code or reload the device. Because SNMP is widely enabled on network gear, this is a serious risk to core routing and switching infrastructure.
Impact
An attacker who can reach the SNMP service gains arbitrary code execution and full control of the affected device, or can force it to reload, disrupting network operations.
Attack surface
Reachable remotely over the network via SNMP on IPv4 or IPv6; no user interaction is required, but the attacker must authenticate, either by knowing the SNMP read-only community string (v1/v2c) or holding valid SNMPv3 user credentials. Only traffic directed to the affected system can be used.
Exploitation
Listed in CISA KEV since 2022-03-03 with a required action to apply vendor updates, and public exploit code exists per reference tags. EPSS is very high at roughly 0.71 (99th percentile), indicating strong likelihood of exploitation activity.
What to do
- Apply the fixed Cisco IOS/IOS XE software identified via the Cisco IOS Software Checker, or apply the vendor workaround from the advisory.
- Disable SNMP where it is not required, and restrict SNMP access to trusted management hosts with ACLs.
- Change default or guessable SNMP community strings and rotate SNMPv3 credentials; prefer SNMPv3 with strong authentication.
- Exclude the affected MIBs/OIDs where the advisory workaround allows, as an interim measure.
- Segment and firewall management-plane access so SNMP is not reachable from untrusted networks.
Detection
- Monitor for unexpected device reloads or crashes correlated with SNMP traffic.
- Alert on SNMP requests from hosts outside the approved management subnet or with anomalous packet sizes/patterns.
- Audit device configurations for enabled SNMP, community strings in use, and SNMP version exposure.
- Review logs for SNMP authentication failures or unusual OID queries preceding a reload.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-6736 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmp | Vendor Advisory |
| http://www.securityfocus.com/bid/99345 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038808 | Broken LinkThird Party AdvisoryVDB Entry |
| https://github.com/artkond/cisco-snmp-rce | Exploit |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmp | Vendor Advisory |
| https://www.exploit-db.com/exploits/43450/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6736 | US Government Resource |
Track CVE-2017-6736 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-6736), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.