CISA KEV · Known exploitedCritical

CVE-2017-3881

Cisco IOS and IOS XE

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges. The Cluster Management Protocol utilizes Telnet internally as a signaling and command protocol between cluster members. The vulnerability is due to the combination of two factors: (1) the failure to restrict the use of CMP-specific Telnet options only to internal, local communications between cluster members and instead accept and process...

CVSS
9.8
EPSS
99.0%
99.9% percentile
CISA KEV
Listed
Published
2017.03.18
PRIORITY ASSESSMENT

Immediate review

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.

Known exploitationConfirmed by CISA KEV
Exploit probability99.0%
Technical severityCVSS 9.8

Vulnerability overview

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges. The Cluster Management Protocol utilizes Telnet internally as a signaling and command protocol between cluster members. The vulnerability is due to the combination of two factors: (1) the failure to restrict the use of CMP-specific Telnet options only to internal, local communications between cluster members and instead accept and process...

Affected product and versions

Product
Cisco IOS and IOS XE
Affected versions
Cisco IOS and IOS XE Software, >= 12.2s <= 15.1\(3\)svs, >= 3.2sg <= 3.9e
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
CISA required action

Apply updates per vendor instructions.

Due date: 2022.04.15
  1. 1
    Identify

    Confirm that Cisco IOS and IOS XE and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-20
KEV added
2022.03.25
Ransomware use
미확인
CVE-2017-3881 — Cisco IOS and IOS XE | SECUFOCUS NOW