NVD disclosure day

Published threat advisories for July 17, 2017

CVE advisoryKnown Exploit

CVE-2017-6744

Cisco IOS SNMP Vulnerabilities Allow Code Execution or System Reload.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A buffer overflow vulnerability in Cisco IOS Software's SNMP subsystem allows authenticated, remote attackers to execute code or cause system reloads. Exploitation requires sending a crafted SNMP packet and may involve knowing community strings or user credentials. Business risk includes unauthorized system control and

• CISA KEV

CVE advisoryKnown Exploit

CVE-2017-6743

Cisco IOS SNMP Vulnerability Allows Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Cisco IOS and IOS XE Software's SNMP subsystem has vulnerabilities that could permit a remote attacker to execute code or cause a system reload by sending a crafted SNMP packet. This poses a business risk of unauthorized system control or service disruption.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2017-6742

Cisco IOS/IOS XE SNMP Vulnerability Allows Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Cisco IOS and IOS XE Software's SNMP implementation allows an authenticated attacker to execute arbitrary code or cause a system reload. Exploitation requires knowledge of SNMP credentials or community strings, posing a risk of system compromise.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2017-6740

Cisco IOS/IOS XE SNMP Vulnerability Allows Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Cisco IOS and IOS XE Software are affected by vulnerabilities in the SNMP subsystem. These flaws could permit an authenticated attacker to execute code or cause system reloads. The risk involves unauthorized control of systems or service disruption.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2017-6739

Cisco IOS SNMP Code Execution and System Reload Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An authenticated attacker can exploit a buffer overflow in the SNMP implementation to execute code or cause system reloads. This impacts affected Cisco systems, posing a risk of unauthorized control or operational disruption. Mitigation involves applying vendor updates and reducing exposure.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2017-6738

Cisco IOS/IOS XE Software SNMP Vulnerability Allows Code Execution.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Cisco IOS and IOS XE Software's SNMP subsystem has vulnerabilities that could allow an authenticated attacker to execute code remotely or cause a system reload. This could result in attackers gaining full control of affected systems or disrupting operations.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2017-6736

Cisco IOS and IOS XE Software SNMP Vulnerability Allows Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Cisco IOS and IOS XE Software contain vulnerabilities in their SNMP subsystem. An authenticated attacker could exploit these flaws to execute code or cause a system reload. Business risk involves potential loss of system control and operational disruption. Organizations should identify affected devices and restrict SNM

• CISA KEV