VDB
CVE-2017-6743
CVE-2017-6743
PUBLISHED
KEV
In Cisco IOS und Cisco IOS XE existieren mehrere Schwachstellen im Zusammenhang mit dem Simple Network Management Protocol (SNMP). Diese Schwachstellen basieren auf einem Buffer Overflow Fehler im SNMP Subsystem.Ein entfernter authentisierter Angreifer kann diese Schwachstellen durch das Senden einer entsprechend bearbeiteten SNMP Anfrage an ein betroffenes System ausnutzen, um beliebigen Code auszuführen und volle Kontrolle über das System zu erlangen oder um ein Neustart des Geräts zu verursachen.
EPSS 20.35% · 95.7th percentile
Risk Scores
EPSS Score
20.35%
95.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco IOS | |
| Cisco | Cisco IOS XE |
Exploit Intelligence
- CIRCL seen: CVE-2017-6743 (circl-sighting)
- CIRCL seen: CVE-2017-6743 (circl-sighting)
- CIRCL seen: CVE-2017-6743 (circl-sighting)
- CIRCL exploited: CVE-2017-6743 (circl-sighting)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-6743 (circl)
- 99345 (circl)
- 1038808 (circl)
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmp (circl)
- cisco-sa-20170629-snmp (circl)
- https://www.ncsc.gov.uk/news/apt28-exploits-known-vulnerability-to-carry-out-reconnaissance-and-deploy-malware-on-cisco-routers (certbund)
…and 17 more exploits
Timeline
- Jun 29, 2017 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- Mar 3, 2022 CISA KEV Added
- May 2, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 11, 2023 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2017/wid-sec-w-2023-0999.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-0999 advisory
- https://www.ncsc.gov.uk/news/apt28-exploits-known-vulnerability-to-carry-out-reconnaissance-and-deploy-malware-on-cisco-routers exploit
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmp advisory
- https://www.exploit-db.com/exploits/43450/ exploit