EXPOSURES › CVE-2017-6742
CVE-2017-6742
HIGH ⌖ ON CISA KEV · EXPLOITEDCisco IOS and IOS XE SNMP RCE vulnerability exploited in the wild
Cisco's SNMP subsystem in IOS and IOS XE Software is vulnerable to remote code execution, allowing authenticated attackers to execute arbitrary code or cause system reloads. This high-severity vulnerability, actively exploited in the wild, highlights systemic issues in Cisco's SNMP and DHCP subsystems, necessitating strict access controls and continuous patching.
Shame score — High-severity RCE vulnerability in Cisco's core networking software, exploited in the wild, indicating systemic issues and lack of timely mitigation.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.
| PRODUCT | STATUS |
|---|---|
| AppDynamics GovAPM AppDynamics (a Cisco company) |
Authorized |
| Cisco Cloudlock for Government Cisco Systems Inc. |
Authorized |
| Cisco Meraki for Government Cisco Systems Inc. |
In Process |
| Cisco SD-WAN for Government Cisco Systems Inc. |
In Process |
| Cisco Umbrella for Government Cisco Systems Inc. |
In Process |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) Cisco Systems Inc. |
Authorized |
| Duo Federal Duo Security (A Cisco Company) |
Authorized |
| WebEx Contact Center Enterprise for Government (WxCCE-G) Cisco Systems Inc. |
In Process |
| Webex for Government Cisco Systems Inc. |
Authorized |