Vulnerability record · CVE-2017-6742 · published 17 July 2017
CVE-2017-6742: Cisco IOS and IOS XE SNMP Buffer Overflow Remote Code Execution
Cisco · Ios
Cisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMP versions 1, 2c, and 3. An authenticated remote attacker can send a crafted SNMP packet to crash the device or execute arbitrary code, making this a serious risk for internet-exposed management interfaces.
Description
A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device. The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or earlier) or the user credentials (SNMPv3). An exploit could allow the attacker to execute arbitrary code and obtain full control of the system or to cause a reload of the affected system. Only traffic directed to the affected system can be used to exploit this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with remote code execution, CISA KEV listing, and high EPSS percentile make this a high-priority patching target despite the authentication requirement.
What it is
Cisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMP versions 1, 2c, and 3. An authenticated remote attacker can send a crafted SNMP packet to crash the device or execute arbitrary code, making this a serious risk for internet-exposed management interfaces.
Impact
Successful exploitation allows arbitrary code execution with full control of the affected device, or a reload that causes a denial of service. Full device compromise can expose routing, switching, and network configuration data.
Attack surface
Reachable over the network via SNMP traffic directed to the affected system; the attacker must supply a valid SNMP read-only community string (v1/v2c) or valid SNMPv3 user credentials. No user interaction is required.
Exploitation
CVE-2017-6742 is listed in CISA's Known Exploited Vulnerabilities catalog, indicating exploitation in the wild, and EPSS shows a 30-day probability of 0.21424 (97.5th percentile). No public exploit code or ransomware association is recorded in this data.
What to do
- Apply the Cisco vendor updates referenced in the Cisco security advisory cisco-sa-20170629-snmp.
- Disable SNMP where it is not required, or restrict SNMP access to trusted management hosts via ACLs.
- Replace default or weak SNMP community strings and rotate SNMPv3 credentials.
- Block SNMP (UDP 161/162) from untrusted networks at the perimeter.
- Monitor for unexpected device reloads and SNMP configuration changes.
Detection
- Alert on unexpected Cisco IOS/IOS XE device reloads or crash dumps.
- Monitor SNMP traffic for malformed or unusually large packets directed at managed devices.
- Audit SNMP community strings and SNMPv3 user accounts for weak or default credentials.
- Review logs for SNMP requests from unauthorized or unexpected source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-6742 to the Known Exploited Vulnerabilities catalog on 19 April 2023 as "Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 10 May 2023.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmp | Vendor Advisory |
| http://www.securityfocus.com/bid/99345 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038808 | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmp | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6742 | US Government Resource |
Track CVE-2017-6742 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-6742), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.