Vulnerability record · CVE-2017-6739 · published 17 July 2017
CVE-2017-6739: Cisco IOS and IOS XE SNMP buffer overflow allows remote code execution
Cisco · Ios
Cisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMP versions 1, 2c, and 3. A remote attacker who knows the SNMP read-only community string or SNMPv3 user credentials can send a crafted SNMP packet to crash the device or execute arbitrary code. Because SNMP is widely enabled on network gear, this is a serious edge-device risk.
Description
A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device. The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or earlier) or the user credentials (SNMPv3). An exploit could allow the attacker to execute arbitrary code and obtain full control of the system or to cause a reload of the affected system. Only traffic directed to the affected system can be used to exploit this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a remotely reachable pre-auth-adjacent buffer overflow leading to code execution or DoS, and it is confirmed in CISA KEV, though exploitation requires valid SNMP credentials.
What it is
Cisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMP versions 1, 2c, and 3. A remote attacker who knows the SNMP read-only community string or SNMPv3 user credentials can send a crafted SNMP packet to crash the device or execute arbitrary code. Because SNMP is widely enabled on network gear, this is a serious edge-device risk.
Impact
Successful exploitation gives the attacker arbitrary code execution and full control of the affected device, or alternatively causes a reload and denial of service.
Attack surface
Reachable remotely over the network by sending a crafted SNMP packet directly to the affected system; the attacker must first possess the SNMP read-only community string (v1/v2c) or valid SNMPv3 user credentials, and no user interaction is required.
Exploitation
CVE-2017-6739 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating real-world exploitation; EPSS shows a 30-day probability of roughly 10.7 percent (95.6th percentile). No ransomware campaign use is documented.
What to do
- Apply the Cisco IOS/IOS XE updates referenced in Cisco advisory cisco-sa-20170629-snmp.
- If SNMP is not required, disable it entirely on affected devices.
- Where SNMP must run, restrict access with ACLs to trusted management hosts and avoid using default or guessable community strings.
- Rotate SNMP community strings and SNMPv3 credentials that may have been exposed.
- Monitor for unexpected device reloads and review SNMP access logs for anomalous sources.
Detection
- Alert on unexpected reloads or crash/restart events on Cisco IOS and IOS XE devices.
- Monitor SNMP traffic for malformed or oversized packets and for SNMP requests from untrusted source addresses.
- Audit SNMP configuration to confirm community strings are non-default and ACLs limit management access.
- Correlate device syslog and SNMP access logs for repeated failed or unusual SNMP requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-6739 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmp | Vendor Advisory |
| http://www.securityfocus.com/bid/99345 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038808 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmp | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6739 | US Government Resource |
Track CVE-2017-6739 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-6739), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.