KEVIntel
9.8
CVSS
Critical

CVE-2017-3881

PUBLISHED

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an...

Exploited in the wild Remote Low complexity No user interaction
Vendor
Cisco
Product
Cisco IOS and IOS XE Software
Published
Mar 17, 2017
EPSS

Description

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges. The Cluster Management Protocol utilizes Telnet internally as a signaling and command protocol between cluster members. The vulnerability is due to the combination of two factors: (1) the failure to restrict the use of CMP-specific Telnet options only to internal, local communications between cluster members and instead accept and process such options over any Telnet connection to an affected device; and (2) the incorrect processing of malformed CMP-specific Telnet options. An attacker could exploit this vulnerability by sending malformed CMP-specific Telnet options while establishing a Telnet session with an affected Cisco device configured to accept Telnet connections. An exploit could allow an attacker to execute arbitrary code and obtain full control of the device or cause a reload of the affected device. This affects Catalyst switches, Embedded Service 2020 switches, Enhanced Layer 2 EtherSwitch Service Module, Enhanced Layer 2/3 EtherSwitch Service Module, Gigabit Ethernet Switch Module (CGESM) for HP, IE Industrial Ethernet switches, ME 4924-10GE switch, RF Gateway 10, and SM-X Layer 2/3 EtherSwitch Service Module. Cisco Bug IDs: CSCvd48893.

ios cisa nuclei_scanner edge

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 10.0

AV:N/AC:L/Au:N/C:C/I:C/A:C

Exploitation status

Exploited in the wild

Recorded 2022-03-25 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Mar 25, 2022

Scanner integrations

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

1337g/CVE-2017-3881

github · Created 2018-01-02 01:45:15 UTC · 2 stars

credit to artkond

mzakyz666/PoC-CVE-2017-3881

github · Created 2017-05-11 12:11:51 UTC · 1 stars

Cisco Catalyst Remote Code Execution PoC

homjxi0e/CVE-2017-3881-Cisco

github · Created 2017-05-02 23:21:53 UTC · 0 stars

homjxi0e/CVE-2017-3881-exploit-cisco-

github · Created 2017-04-20 00:52:10 UTC · 2 stars

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nuclei