CVE-2017-6744 is a critical buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software. An authenticated, remote attacker can exploit this by sending a crafted SNMP packet, affecting all SNMP versions (1, 2c, and 3). Successful exploitation allows arbitrary code execution, leading to full system control or a reload. This vulnerability has a CVSS score of 8.8 (High), indicating a network-based attack with low complexity and high impact on confidentiality, integrity, and availability. It is listed in CISA's KEV catalog, confirming active exploitation, though no public exploit code is readily available via Metasploit, Nuclei, or ExploitDB. Community discussion is high, suggesting significant attention despite a lack of media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.2\(33\)sxiCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(33\)sxi:*:*:*:*:*:*:* | ||
12.2\(33\)sxi1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(33\)sxi1:*:*:*:*:*:*:* | ||
12.2\(50\)seCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(50\)se:*:*:*:*:*:*:* | ||
12.2\(50\)se1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(50\)se1:*:*:*:*:*:*:* | ||
12.2\(50\)se2CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(50\)se2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.