Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.
- Vendor
- Cisco
- Product
- IOS and IOS XE Software
- CVSS
- 8.8
- EPSS (exploit probability)
- 21.4%
- Status
- kev
- CISA patch-by (BOD 22-01)
- Published
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.
Added to CISA’s Known Exploited Vulnerabilities catalog on 2023-04-19. Required action per CISA: Apply updates per vendor instructions. Due date: 2023-05-10.
This is an auto-synced KEV catalog record pending a full 0dayNews write-up — see CISA’s KEV catalog and the NVD record linked above for primary sources.