Skip to content
COOEY

EXPOSURES › CVE-2017-6742

CVE-2017-6742

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-04-19 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2017-6742 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Cisco IOS and IOS XE SNMP RCE vulnerability exploited in the wild

Cisco's SNMP subsystem in IOS and IOS XE Software is vulnerable to remote code execution, allowing authenticated attackers to execute arbitrary code or cause system reloads. This high-severity vulnerability, actively exploited in the wild, highlights systemic issues in Cisco's SNMP and DHCP subsystems, necessitating strict access controls and continuous patching.

Shame score — High-severity RCE vulnerability in Cisco's core networking software, exploited in the wild, indicating systemic issues and lack of timely mitigation.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.

AFFECTED FEDRAMP PRODUCTS · 9
PRODUCTSTATUS
AppDynamics GovAPM
AppDynamics (a Cisco company)
Authorized
Cisco Cloudlock for Government
Cisco Systems Inc.
Authorized
Cisco Meraki for Government
Cisco Systems Inc.
In Process
Cisco SD-WAN for Government
Cisco Systems Inc.
In Process
Cisco Umbrella for Government
Cisco Systems Inc.
In Process
Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
Cisco Systems Inc.
Authorized
Duo Federal
Duo Security (A Cisco Company)
Authorized
WebEx Contact Center Enterprise for Government (WxCCE-G)
Cisco Systems Inc.
In Process
Webex for Government
Cisco Systems Inc.
Authorized