CVE-2017-6743 is a critical buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software. An authenticated, remote attacker can exploit this by sending a crafted SNMP packet, potentially leading to remote code execution or system reload. With a CVSS score of 8.8 (High) and a FAUCET Risk Score of 99/100, successful exploitation grants full control over the affected system. This vulnerability is actively exploited (KEV listed), despite a lack of public exploit code or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.0, <= 12.4CPE matchmatch criteria | cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:* | ||
>= 15.0, <= 15.6CPE matchmatch criteria | cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:* | ||
>= 2.2.0, <= 3.17CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.