Loading HuntDB...

Cisco IOS and IOS XE Remote Code Execution Vulnerability

Added March 25, 2022 Due April 15, 2022 CVE-2017-3881
Overdue Cisco / IOS and IOS XE CWE-20

Description

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges.

Required Action

Apply updates per vendor instructions.

References

Additional Information

Catalog Version
2025.01.24
Catalog Released
Jan. 24, 2025
Days Until Due
0 days
Last Updated
6 months ago