LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-6743: Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-6743 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.

CVE-2017-6743 is a remote code execution vulnerability in the SNMP subsystem of Cisco IOS and IOS XE Software. An authenticated remote attacker who can reach the SNMP service may be able to execute code on the device. Network infrastructure that exposes SNMP is a high-value target, so teams should treat this class of flaw as urgent and confirm exposure against the vendor advisory.

Public detail is limited to the facts above. Exact affected releases, CVSS scores, and exploit mechanics must be taken from Cisco’s advisory; do not rely on secondary summaries alone.

How it works

The weakness is classified as CWE-119 (improper restriction of operations within the bounds of a memory buffer). In practice this means the SNMP subsystem does not correctly bound or validate certain input before using it in memory operations. An attacker who authenticates to SNMP and sends crafted protocol data can trigger the flaw and achieve remote code execution on the device.

Because SNMP is commonly used for monitoring and management, the attack path is network-reachable once credentials (or community strings, depending on SNMP version and configuration) are known or obtained. The CISA summary states the attacker must be authenticated and remote; no further exploit steps are provided in the given facts, so defenders should assume a successful trigger leads to full control of the affected IOS/IOS XE process and treat the device as compromised until proven otherwise.

Am I affected? How to find it in your systems

Cisco IOS and IOS XE run on a wide range of enterprise routers, switches, and related network platforms. Inventory every device that could be running these operating systems, including branch, campus, data-center, and any management or lab gear that still has SNMP enabled.

If your inventory tooling cannot reliably map every IOS/IOS XE image, treat unknown devices that answer SNMP as potentially affected until you confirm the image train and advisory status.

How to remediate

Patch first. Apply the updates Cisco published for this vulnerability, following the vendor instructions referenced by CISA (“Apply updates per vendor instructions”). Schedule maintenance windows for production routers and switches, verify the target image in a lab or canary device, then roll out with standard change control and post-upgrade validation (routing adjacency, SNMP polling, and configuration integrity).

Document the advisory ID, the images you deployed, and the devices that remain on older trains so residual risk is visible.

If you can't patch immediately

Until the vendor update is installed, reduce the attack surface and increase detection:

These steps do not eliminate the memory-corruption risk; they only buy time until the official update is applied.

If your data may have been exposed

Actively exploited remote-code-execution flaws on network devices can lead to full device compromise, traffic interception, credential theft, and lateral movement into adjacent systems. Known ransomware use is not documented for this CVE in the provided facts, but any successful code execution should still be treated as a potential breach of the device and of data that traversed or was reachable from it. Rotate credentials stored on or used by the device, review configuration and flow records for unauthorized changes, and follow your incident-response process. You can run a free exposure scan of your email addresses against known breach data sets to see whether related accounts appear in prior incidents while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · IOS and IOS XE Software
WeaknessCWE-119
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 24, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities