CVE-2017-6742 is a critical buffer overflow vulnerability in the SNMP implementation of Cisco IOS and IOS XE, affecting all SNMP versions. An authenticated, remote attacker can exploit this by sending a crafted SNMP packet to gain full control of the system or cause a denial of service. With a CVSS score of 8.8 (HIGH) and a FAUCET Risk Score of 99/100, this vulnerability requires prior authentication (SNMP community string or user credentials) but has a low attack complexity. This CVE is actively exploited in the wild, as confirmed by its presence in the KEV catalog and recent warnings from NCSC regarding Russian state-sponsored actors. Despite active exploitation, there are no public Metasploit or ExploitDB modules, though it has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.0, <= 12.4CPE matchmatch criteria | cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:* | ||
>= 15.0, <= 15.6CPE matchmatch criteria | cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:* | ||
>= 2.2.0, <= 3.17CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.