Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

Added to KEV
2023-04-19
Federal due date
2023-05-10
Vendor
Cisco
Product
IOS and IOS XE Software
EPSS
94.6th percentile (score 0.148, as of 2026-06-08)
NVD CVSS v3.1
Ransomware use
Unknown
Upstream
https://nvd.nist.gov/vuln/detail/CVE-2017-6742

CISA short description

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.

Required action

Apply updates per vendor instructions.

EPSS percentile is the FIRST.org exploit-probability ranking as of the date noted above; it moves daily. CVSS reflects NVD's analysis at time of publication.