Aller au contenu
Toutes les vulnérabilités
CVE-2017-6743KEV

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

Sévérité
Élevée8,8CVSS 3.1, Élevée
EPSS
11 %
Publiée
17 juil. 2017
Mise à jour
17 juin 2026

Description

Le titre, la description et les consignes de l’éditeur sont cités depuis les enregistrements sources (en anglais).

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP - Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or earlier, the attacker must know the SNMP read-only community string for the affected system. To exploit these vulnerabilities via SNMP Version 3, the attacker must have user credentials for the affected system. A successful exploit could allow the attacker to execute arbitrary code and obtain full control of the affected system or cause the affected system to reload. Customers are advised to apply the workaround as contained in the Workarounds section below. Fixed software information is available via the Cisco IOS Software Checker. All devices that have enabled SNMP and have not explicitly excluded the affected MIBs or OIDs should be considered vulnerable. There are workarounds that address these vulnerabilities.

Faiblesse : CWE-119

Exploitée activement

Ajoutée au catalogue CISA KEV le 3 mars 2022

Date limite de remédiation fédérale : 24 mars 2022

Action requise : Apply updates per vendor instructions.

Prédiction d’exploitation

Probabilité d’exploitation de 11 % dans les 30 prochains jours (percentile 96 %).

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Produits concernés

Patcharo affiche cette vulnérabilité à titre d’information mais ne compare pas encore les versions de ce produit.

  • Cisco IOS · 12.1(3)XI, 12.2(1b)DA, 12.2(5)DA, 12.2(7)DA, 12.2(12)DA, 12.2(10)DA5, 12.2(12)DA10, 12.2(10)DA, 12.2(12)DA1, 12.2(12)DA6, 12.2(10)DA8, 12.2(12)DA8 et 781 autres
  • IntelliShield Universal Product · N/A

Références

Provenance

Chaque information de cette page provient des sources ci-dessous. Rien n’est rédigé par une IA.

Cisco (CVE record)
Cisco (CVE record) · 27 sept. 2026, 23:46 UTC · Analyseur patcharo-cve5/1.1.0
CISA Known Exploited Vulnerabilities
CISA Known Exploited Vulnerabilities · 27 sept. 2026, 23:42 UTC · Analyseur patcharo-kev/1.0.0
NVD
NVD · 27 sept. 2026, 23:44 UTC · Analyseur patcharo-nvd/1.0.0
FIRST EPSS
FIRST EPSS · 27 sept. 2026, 23:46 UTC · Analyseur patcharo-epss/1.0.0

Dernière vérification : 28 sept. 2026, 02:31 UTC