CVE-2017-6737 is a critical buffer overflow vulnerability in the SNMP implementation of Cisco IOS and IOS XE, allowing authenticated remote attackers to execute arbitrary code or cause a system reload. With a CVSS score of 8.8 (HIGH), it requires an attacker to send a crafted SNMP packet and know either the SNMP community string or user credentials. This vulnerability has been actively exploited (KEV) and has a high FAUCET Risk Score of 99/100, despite no public Metasploit or ExploitDB modules. It has garnered significant community discussion and media coverage, indicating its importance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.0, <= 12.4CPE matchmatch criteria | cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:* | ||
>= 15.0, <= 15.6CPE matchmatch criteria | cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:* | ||
>= 2.2.0, <= 3.17.0CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.