LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-6739: Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-6739 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected…

CVE-2017-6739 is a remote code execution vulnerability in the SNMP subsystem of Cisco IOS and IOS XE Software. An authenticated remote attacker who can reach SNMP on an affected device may execute code or force a reload, which can disrupt network operations or give an attacker a foothold on core infrastructure.

Because routers and switches running IOS/IOS XE often sit at the center of enterprise and service-provider networks, successful abuse can affect availability and open a path to further compromise. Confirm exact impact and fixed releases against the vendor advisory.

How it works

The weakness is classified as CWE-119 (improper restriction of operations within the bounds of a memory buffer). In broad terms for this class, flawed handling of SNMP-related input can corrupt memory in the SNMP process on the device.

According to the CISA summary, an authenticated, remote attacker who can interact with the SNMP subsystem may trigger the flaw to execute code on the affected system or cause it to reload. Public detail in the provided record does not describe packet formats, OID specifics, or exploit mechanics; treat any such claims as unconfirmed unless they appear in the vendor advisory. Authentication is required, so the attacker needs valid SNMP credentials (or equivalent access) and network reachability to the SNMP service.

Am I affected? How to find it in your systems

Cisco IOS and IOS XE commonly run on enterprise and service-provider routers, switches, and related network platforms. Inventory every device that might still run these operating systems, including branch, campus, data-center, and management-plane gear.

How to remediate

Patch first. Apply the updates Cisco designates for CVE-2017-6739, following the vendor’s installation and reload procedures for IOS and IOS XE. CISA’s required action is to apply updates per vendor instructions.

If you can't patch immediately

Reduce exposure until you can install the vendor fix.

If your data may have been exposed

Actively exploited remote-code-execution flaws on network devices can lead to broader intrusion and data exposure even when ransomware use is not documented for this CVE. If you suspect compromise, isolate affected devices, preserve logs and memory/crashinfo where possible, rotate credentials and keys that traversed the device, and follow your incident-response process. You can also run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in prior breaches while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · IOS and IOS XE Software
WeaknessCWE-119
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 24, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities