{"cveID":"CVE-2017-6742","vendorProject":"Cisco","product":"IOS and IOS XE Software","vulnerabilityName":"Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability","dateAdded":"2023-04-19","shortDescription":"The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2023-05-10","knownRansomwareCampaignUse":"Unknown","notes":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmp; https://nvd.nist.gov/vuln/detail/CVE-2017-6742","cwes":["CWE-119"],"year":2017,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2017-6742","technique":"T1574","technique_name_at_mapping":"Hijack Execution Flow","mapping_type":"exploitation_technique","capability_group":"code_execution","comments":"CVE-2017-6742 is a Simple Network Management Protocol (SNMP) vulnerability in Cisco products related to a buffer overflow condition in the SNMP subsystem. \nReported by the NCSC, threat actors exploited CVE-2017-6742 to perform reconnaissance, enumerate router interfaces and deploy custom malware known as \"Jaguar Tooth\", as detailed in the NCSC’s Jaguar Tooth malware analysis report. This malware obtains further device information which is then exfiltrated over trivial file transfer protocol (TFTP) and enables unauthenticated access via a backdoor.","references":["https://digital.nhs.uk/cyber-alerts/2023/cc-4303","https://cyble.com/blog/cisco-routers-exploited-by-russian-state-sponsored-attackers/","https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-108"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2017-6742","technique":"T1048","technique_name_at_mapping":"Exfiltration Over Alternative Protocol","mapping_type":"secondary_impact","capability_group":"code_execution","comments":"CVE-2017-6742 is a Simple Network Management Protocol (SNMP) vulnerability in Cisco products related to a buffer overflow condition in the SNMP subsystem. \nReported by the NCSC, threat actors exploited CVE-2017-6742 to perform reconnaissance, enumerate router interfaces and deploy custom malware known as \"Jaguar Tooth\", as detailed in the NCSC’s Jaguar Tooth malware analysis report. This malware obtains further device information which is then exfiltrated over trivial file transfer protocol (TFTP) and enables unauthenticated access via a backdoor.","references":["https://digital.nhs.uk/cyber-alerts/2023/cc-4303","https://cyble.com/blog/cisco-routers-exploited-by-russian-state-sponsored-attackers/","https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-108"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2017-6742","technique":"T1059","technique_name_at_mapping":"Command and Scripting Interpreter","mapping_type":"primary_impact","capability_group":"code_execution","comments":"CVE-2017-6742 is a Simple Network Management Protocol (SNMP) vulnerability in Cisco products related to a buffer overflow condition in the SNMP subsystem. \nReported by the NCSC, threat actors exploited CVE-2017-6742 to perform reconnaissance, enumerate router interfaces and deploy custom malware known as \"Jaguar Tooth\", as detailed in the NCSC’s Jaguar Tooth malware analysis report. This malware obtains further device information which is then exfiltrated over trivial file transfer protocol (TFTP) and enables unauthenticated access via a backdoor.","references":["https://digital.nhs.uk/cyber-alerts/2023/cc-4303","https://cyble.com/blog/cisco-routers-exploited-by-russian-state-sponsored-attackers/","https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-108"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2017-6742","technique":"T1542.005","technique_name_at_mapping":"TFTP Boot","mapping_type":"secondary_impact","capability_group":"code_execution","comments":"CVE-2017-6742 is a Simple Network Management Protocol (SNMP) vulnerability in Cisco products related to a buffer overflow condition in the SNMP subsystem. \nReported by the NCSC, threat actors exploited CVE-2017-6742 to perform reconnaissance, enumerate router interfaces and deploy custom malware known as \"Jaguar Tooth\", as detailed in the NCSC’s Jaguar Tooth malware analysis report. This malware obtains further device information which is then exfiltrated over trivial file transfer protocol (TFTP) and enables unauthenticated access via a backdoor.","references":["https://digital.nhs.uk/cyber-alerts/2023/cc-4303","https://cyble.com/blog/cisco-routers-exploited-by-russian-state-sponsored-attackers/","https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-108"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1048","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exfiltration Over Alternative Protocol","name_at_mapping":"Exfiltration Over Alternative Protocol","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":12,"has_detection_strategy":true},{"id":"T1059","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Command and Scripting Interpreter","name_at_mapping":"Command and Scripting Interpreter","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":95,"has_detection_strategy":true},{"id":"T1542.005","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"TFTP Boot","name_at_mapping":"TFTP Boot","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":0,"has_detection_strategy":true},{"id":"T1574","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Hijack Execution Flow","name_at_mapping":"Hijack Execution Flow","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":8,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"partial","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}