CVE-2017-6742

HIGH KEV

Cisco IOS and IOS XE - Authenticated Remote Code Execution via SNMP Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2017-6742 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added April 19, 2023. EIP tracks 2 public exploits from researchers including sastraadiwiguna-purpleeliteteaming.

AI-analyzed exploit summary This repository provides a detailed technical analysis and reconstruction of the JAGUAR_TOOTH malware targeting CVE-2017-6742 in Cisco IOS. It includes impact analysis, research methodology, and disclaimers but lacks functional exploit code.

Description

A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device.  The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or earlier) or the user credentials (SNMPv3). An exploit could allow the attacker to execute arbitrary code and obtain full control of the system or to cause a reload of the affected system. Only traffic directed to the affected system can be used to exploit this vulnerability.

Exploits (2)

gitlab WRITEUP
by sastraadiwiguna-purpleeliteteaming · poc
https://gitlab.com/sastraadiwiguna-purpleeliteteaming/cisco-ios-exploitation-jaguar_tooth-cve-2017-6742-reconstruction

This repository provides a detailed technical analysis and reconstruction of the JAGUAR_TOOTH malware targeting CVE-2017-6742 in Cisco IOS. It includes impact analysis, research methodology, and disclaimers but lacks functional exploit code.

Classification
Writeup 95%
Attack Type
Other
Complexity
Complex
Reliability
Theoretical
Target: Cisco IOS firmware C5350-IS-M version 12.3(6)
No auth needed
Prerequisites: Access to vulnerable Cisco IOS firmware · Knowledge of MIPS architecture and ROP chains
devstral-2 · analyzed Feb 23, 2026 Full analysis →
nomisec WRITEUP
by sastraadiwiguna-purpleeliteteaming · poc
https://github.com/sastraadiwiguna-purpleeliteteaming/Cisco-IOS-Exploitation-JAGUAR_TOOTH-CVE-2017-6742-Reconstruction

This repository provides a detailed technical analysis and reconstruction of the JAGUAR_TOOTH malware, which exploits CVE-2017-6742, a stack-based buffer overflow in Cisco IOS SNMP. It includes mitigation strategies and indicators of compromise.

Classification
Writeup 100%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Cisco IOS 12.3(6)
No auth needed
Prerequisites: Access to vulnerable Cisco IOS device with SNMP enabled · Network access to target device on UDP/161
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.2142
EPSS Percentile 97.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2023-04-19
VulnCheck KEV 2023-04-17
InTheWild.io 2023-04-19
ENISA EUVD EUVD-2017-15796
CWE
CWE-119
Status published
Products (50)
Cisco/Cisco IOS XE Software 16.2.1
Cisco/Cisco IOS XE Software 16.2.2
Cisco/Cisco IOS XE Software 16.3.1
Cisco/Cisco IOS XE Software 16.3.1a
Cisco/Cisco IOS XE Software 16.3.2
Cisco/Cisco IOS XE Software 16.3.3
Cisco/Cisco IOS XE Software 16.3.4
Cisco/Cisco IOS XE Software 16.4.1
Cisco/Cisco IOS XE Software 16.4.2
Cisco/Cisco IOS XE Software 16.5.1
... and 40 more
Published Jul 17, 2017
KEV Added Apr 19, 2023
Tracked Since Feb 18, 2026