Vulnerability record · CVE-2017-6737 · published 17 July 2017
CVE-2017-6737: Cisco IOS and IOS XE SNMP Buffer Overflow RCE
Cisco · Ios
Cisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMPv1, v2c, and v3. An authenticated remote attacker who knows the SNMP read-only community string or SNMPv3 credentials can send a crafted SNMP packet to crash the device or execute arbitrary code.
Description
A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device. The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or earlier) or the user credentials (SNMPv3). An exploit could allow the attacker to execute arbitrary code and obtain full control of the system or to cause a reload of the affected system. Only traffic directed to the affected system can be used to exploit this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw allows remote code execution with full device control, is listed in CISA KEV, and carries a very high EPSS score, making it a top remediation priority.
What it is
Cisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMPv1, v2c, and v3. An authenticated remote attacker who knows the SNMP read-only community string or SNMPv3 credentials can send a crafted SNMP packet to crash the device or execute arbitrary code.
Impact
Successful exploitation gives the attacker arbitrary code execution and full control of the affected device, or alternatively causes a reload, disrupting network operations.
Attack surface
Reachable over the network by sending a crafted SNMP packet directly to the affected device; the attacker must first possess the SNMP read-only community string (v1/v2c) or valid SNMPv3 user credentials, and no user interaction is required.
Exploitation
CVE-2017-6737 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03) and has a high EPSS probability of 0.44325 (98.7th percentile), indicating active exploitation is expected; no ransomware campaign use is documented.
What to do
- Apply the Cisco IOS/IOS XE updates referenced in Cisco advisory cisco-sa-20170629-snmp.
- Disable SNMP on devices that do not require it, and restrict SNMP access to trusted management hosts via ACLs.
- Replace SNMPv1/v2c read-only community strings with SNMPv3 and strong credentials, and rotate any exposed community strings.
- Monitor and restrict management-plane traffic so only authorized sources can reach SNMP services.
Detection
- Inspect SNMP traffic for malformed or oversized packets targeting UDP 161 on Cisco IOS/IOS XE devices.
- Alert on unexpected device reloads or crashes correlated with SNMP request bursts.
- Log and review SNMP authentication attempts, especially failures or use of default/weak community strings.
- Monitor for anomalous processes or configuration changes on network devices that could indicate post-exploitation code execution.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-6737 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmp | Vendor Advisory |
| http://www.securityfocus.com/bid/99345 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038808 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmp | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6737 | US Government Resource |
Track CVE-2017-6737 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-6737), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.