Vulnerability record · CVE-2017-6743 · published 17 July 2017
CVE-2017-6743: Cisco IOS and IOS XE SNMP buffer overflow allows remote code execution
Cisco · Ios
The SNMP subsystem in Cisco IOS and IOS XE Software contains a buffer overflow that an authenticated, remote attacker can trigger with a crafted SNMP packet sent over IPv4 or IPv6. It affects SNMP versions 1, 2c and 3, and a successful exploit can execute arbitrary code or reload the device. Because SNMP is widely enabled on network infrastructure, this is a serious risk to routers and switches.
Description
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP - Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or earlier, the attacker must know the SNMP read-only community string for the affected system. To exploit these vulnerabilities via SNMP Version 3, the attacker must have user credentials for the affected system. A successful exploit could allow the attacker to execute arbitrary code and obtain full control of the affected system or cause the affected system to reload. Customers are advised to apply the workaround as contained in the Workarounds section below. Fixed software information is available via the Cisco IOS Software Checker. All devices that have enabled SNMP and have not explicitly excluded the affected MIBs or OIDs should be considered vulnerable. There are workarounds that address these vulnerabilities.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows remote code execution with high confidentiality, integrity and availability impact, is listed in CISA KEV, and affects widely deployed network infrastructure, though exploitation requires valid SNMP credentials.
What it is
The SNMP subsystem in Cisco IOS and IOS XE Software contains a buffer overflow that an authenticated, remote attacker can trigger with a crafted SNMP packet sent over IPv4 or IPv6. It affects SNMP versions 1, 2c and 3, and a successful exploit can execute arbitrary code or reload the device. Because SNMP is widely enabled on network infrastructure, this is a serious risk to routers and switches.
Impact
An attacker gains arbitrary code execution and full control of the affected device, or can force it to reload, causing a denial of service. Control of a router or switch can expose or disrupt the traffic it handles.
Attack surface
Reachable remotely over the network via crafted SNMP packets to the device's SNMP service on IPv4 or IPv6; only traffic directed at the affected system can be used. Authentication is required: SNMPv2c or earlier needs the read-only community string, and SNMPv3 needs valid user credentials. No user interaction is needed.
Exploitation
CVE-2017-6743 is listed in CISA's Known Exploited Vulnerabilities catalog, indicating real-world exploitation, and its EPSS 30-day probability is about 10.7 percent (95th percentile). No ransomware campaign use is documented in the record.
What to do
- Apply the fixed Cisco IOS or IOS XE software identified through the Cisco IOS Software Checker, per the vendor advisory.
- If patching cannot be done immediately, apply the workarounds in the Cisco advisory, including restricting or disabling SNMP and excluding the affected MIBs or OIDs.
- Restrict SNMP access with ACLs so only trusted management hosts can reach UDP 161/162, and disable SNMP on devices that do not need it.
- Replace SNMPv1/v2c community strings with SNMPv3 and strong credentials, and rotate any exposed community strings.
- Monitor Cisco advisories for updated fixed-software guidance for IOS and IOS XE.
Detection
- Alert on SNMP traffic to managed devices from hosts outside the approved management network or ACL range.
- Inspect SNMP request patterns for malformed or oversized packets and unexpected OID requests targeting the affected MIBs.
- Monitor device logs and syslog for unexpected reloads, crashes or SNMP process restarts on IOS and IOS XE devices.
- Track SNMP community string use and authentication failures on SNMPv3 to spot credential abuse.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-6743 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmp | Vendor Advisory |
| http://www.securityfocus.com/bid/99345 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038808 | Third Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmp | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6743 | US Government Resource |
Track CVE-2017-6743 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-6743), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.