Vulnerability record · CVE-2017-6740 · published 17 July 2017
CVE-2017-6740: Cisco IOS and IOS XE SNMP buffer overflow allows remote code execution
Cisco · Ios
Cisco IOS and IOS XE contain a buffer overflow in the SNMP subsystem affecting SNMP versions 1, 2c, and 3. An authenticated remote attacker can send a crafted SNMP packet over IPv4 or IPv6 to execute code or force a device reload. Because SNMP is widely enabled on network infrastructure, a compromised device can give an attacker a foothold deep inside the network.
Description
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP - Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or earlier, the attacker must know the SNMP read-only community string for the affected system. To exploit these vulnerabilities via SNMP Version 3, the attacker must have user credentials for the affected system. A successful exploit could allow the attacker to execute arbitrary code and obtain full control of the affected system or cause the affected system to reload. Customers are advised to apply the workaround as contained in the Workarounds section below. Fixed software information is available via the Cisco IOS Software Checker. All devices that have enabled SNMP and have not explicitly excluded the affected MIBs or OIDs should be considered vulnerable. There are workarounds that address these vulnerabilities.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows authenticated remote code execution with full device compromise, is listed in CISA KEV as exploited, and affects widely deployed network infrastructure, though exploitation requires valid SNMP credentials.
What it is
Cisco IOS and IOS XE contain a buffer overflow in the SNMP subsystem affecting SNMP versions 1, 2c, and 3. An authenticated remote attacker can send a crafted SNMP packet over IPv4 or IPv6 to execute code or force a device reload. Because SNMP is widely enabled on network infrastructure, a compromised device can give an attacker a foothold deep inside the network.
Impact
Successful exploitation lets the attacker execute arbitrary code and gain full control of the affected device, or cause it to reload, disrupting network operations.
Attack surface
Reachable remotely over IPv4 or IPv6 by sending a crafted SNMP packet directly to the affected system. Exploitation requires authentication: the SNMP read-only community string for SNMPv2c or earlier, or valid user credentials for SNMPv3; no user interaction is needed.
Exploitation
CVE-2017-6740 is listed in CISA KEV with a 2022-03-03 addition date and a 2022-03-24 remediation due date, indicating known exploitation in the wild. EPSS gives a 30-day exploitation probability of roughly 10.9 percent (95.6th percentile), and no ransomware campaign use is documented.
What to do
- Apply the fixed software identified through the Cisco IOS Software Checker, or the workaround in the Cisco advisory, as the primary remediation.
- Disable SNMP where it is not required, and restrict SNMP access to trusted management hosts via ACLs.
- Explicitly exclude the affected MIBs or OIDs where the advisory workaround permits.
- Replace SNMPv1/v2c community strings with SNMPv3 credentials and rotate any exposed community strings.
- Monitor for and block unauthorized SNMP traffic at network boundaries.
Detection
- Alert on SNMP traffic to IOS/IOS XE devices from hosts outside the approved management subnet.
- Monitor device logs and syslog for unexpected reloads, crashes, or SNMP-related fault messages.
- Baseline and review SNMP community strings and SNMPv3 user accounts for unauthorized changes.
- Use network flow or IDS signatures to detect malformed or oversized SNMP packets directed at infrastructure devices.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-6740 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmp | US Government Resource |
| http://www.securityfocus.com/bid/99345 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038808 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmp | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6740 | US Government Resource |
Track CVE-2017-6740 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-6740), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.