← Vulnerability feed

Vulnerability record · CVE-2017-6744 · published 17 July 2017

CVE-2017-6744: Cisco IOS and IOS XE SNMP buffer overflow allows remote code execution

Cisco · Ios

The SNMP subsystem in Cisco IOS and IOS XE Software contains a buffer overflow that affects SNMP versions 1, 2c, and 3. An authenticated, remote attacker can send a crafted SNMP packet over IPv4 or IPv6 to execute code or force a device reload, making it a serious risk for internet- or management-reachable network gear.

8.8 CVSS 3.1 High CISA KEV since 3 Mar 2022 EPSS 7.3% · top 5.8% CWE-119 · Memory buffer overflow
8.8CVSS 3.1 base score, v2 9.0
7.3%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP - Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or earlier, the attacker must know the SNMP read-only community string for the affected system. To exploit these vulnerabilities via SNMP Version 3, the attacker must have user credentials for the affected system. A successful exploit could allow the attacker to execute arbitrary code and obtain full control of the affected system or cause the affected system to reload. Customers are advised to apply the workaround as contained in the Workarounds section below. Fixed software information is available via the Cisco IOS Software Checker. All devices that have enabled SNMP and have not explicitly excluded the affected MIBs or OIDs should be considered vulnerable. There are workarounds that address these vulnerabilities.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw allows remote code execution with full device control and is in CISA's KEV catalog, though exploitation requires valid SNMP credentials or a known community string.

What it is

The SNMP subsystem in Cisco IOS and IOS XE Software contains a buffer overflow that affects SNMP versions 1, 2c, and 3. An authenticated, remote attacker can send a crafted SNMP packet over IPv4 or IPv6 to execute code or force a device reload, making it a serious risk for internet- or management-reachable network gear.

Impact

A successful exploit gives the attacker arbitrary code execution and full control of the affected device, or causes it to reload, disrupting network operations.

Attack surface

Reached remotely by sending a crafted SNMP packet to the device over IPv4 or IPv6; only traffic directed at the affected system works. Authentication is required: the SNMP read-only community string for v2c or earlier, or valid user credentials for SNMP v3. No user interaction is needed.

Exploitation

CVE-2017-6744 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03), indicating exploitation in the wild; EPSS gives a 30-day probability of about 7.2 percent (94th percentile). No ransomware campaign use is documented.

What to do

  • Apply the fixed Cisco IOS/IOS XE software identified via the Cisco IOS Software Checker, or apply the vendor workaround in the advisory.
  • Disable SNMP where it is not required, or restrict access to affected MIBs/OIDs as described in the advisory.
  • Replace default or guessable SNMP community strings and use SNMPv3 with strong credentials where SNMP must remain enabled.
  • Restrict SNMP access with ACLs and infrastructure ACLs so only trusted management hosts can reach UDP 161/162.
  • Monitor for and block unauthorized SNMP traffic at network boundaries.

Detection

  • Alert on SNMP packets to UDP 161/162 from hosts outside the approved management subnet.
  • Monitor device logs for unexpected reloads, crashes, or SNMP-related error messages.
  • Baseline and alert on changes to SNMP configuration, community strings, or ACLs on IOS/IOS XE devices.
  • Watch for unusual outbound connections or process behavior from network devices that could indicate post-exploitation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-6744 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Cisco IOS Software SNMP Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-6744 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-0171Cisco IOS Smart Install improper input validation allows remote code executionCisco IOS and IOS XE Smart Install fails to properly validate packet data, so a crafted Smart Install message sent to TCP port 4786 can overflow a bu…KEVEPSS 99%analysed9.8CVE-2017-12240Cisco IOS and IOS XE DHCP Relay Buffer Overflow RCEThe DHCP relay subsystem in Cisco IOS 12.2 through 15.6 and Cisco IOS XE contains a buffer overflow caused by improper input validation of DHCPv4 pac…KEVEPSS 14%analysed9.8CVE-2017-3881Cisco IOS/IOS XE CMP Telnet Option Handling RCECisco IOS and IOS XE fail to restrict CMP-specific Telnet options to internal cluster communications and mishandle malformed CMP Telnet options, so a…KEVEPSS 99%analysed8.8CVE-2018-0167Cisco IOS, IOS XE and IOS XR LLDP buffer overflowMultiple buffer overflow flaws exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.4%analysed8.8CVE-2017-6736Cisco IOS and IOS XE SNMP buffer overflow remote code executionThe SNMP subsystem in Cisco IOS and IOS XE contains a buffer overflow that can be triggered by a crafted SNMP packet sent over IPv4 or IPv6. It affec…KEVEPSS 70%analysed8.8CVE-2017-6737Cisco IOS and IOS XE SNMP Buffer Overflow RCECisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMPv1, v2c, and v3. An authenticated remote attacker who know…KEVEPSS 45%analysed8.8CVE-2017-6738Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionThe SNMP subsystem in Cisco IOS and IOS XE Software contains a buffer overflow that affects SNMP versions 1, 2c, and 3. An authenticated remote attac…KEVEPSS 11%analysed8.8CVE-2017-6739Cisco IOS and IOS XE SNMP buffer overflow allows remote code executionCisco IOS and IOS XE contain a buffer overflow in the SNMP implementation that affects SNMP versions 1, 2c, and 3. A remote attacker who knows the SN…KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-2017-6744), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.