CVE-2017-6737 - Improper Restriction of Operations within the Bounds of a Memory Buffer

Severity

90%

Complexity

80%

Confidentiality

165%

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 2.2 through 3.17 contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP: Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or earlier, the attacker must know the SNMP read-only community string for the affected system. To exploit these vulnerabilities via SNMP Version 3, the attacker must have user credentials for the affected system. All devices that have enabled SNMP and have not explicitly excluded the affected MIBs or OIDs should be considered vulnerable. Cisco Bug IDs: CSCve60402.

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 2.2 through 3.17 contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP: Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or earlier, the attacker must know the SNMP read-only community string for the affected system. To exploit these vulnerabilities via SNMP Version 3, the attacker must have user credentials for the affected system. All devices that have enabled SNMP and have not explicitly excluded the affected MIBs or OIDs should be considered vulnerable. Cisco Bug IDs: CSCve60402.

CVSS 3.0 Base Score 8.8. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS 2.0 Base Score 9. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (AV:N/AC:L/Au:S/C:C/I:C/A:C).

Demo Examples

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-119

This example takes an IP address from a user, verifies that it is well formed and then looks up the hostname and copies it into a buffer.


               
}
strcpy(hostname, hp->h_name);/*routine that ensures user_supplied_addr is in the right format for conversion */

This function allocates a buffer of 64 bytes to store the hostname, however there is no guarantee that the hostname will not be larger than 64 bytes. If an attacker specifies an address which resolves to a very large hostname, then we may overwrite sensitive data or even relinquish control flow to the attacker.

Note that this example also contains an unchecked return value (CWE-252) that can lead to a NULL pointer dereference (CWE-476).

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-119

This example applies an encoding procedure to an input string and stores it into a buffer.


               
}
return dst_buf;
die("user string too long, die evil hacker!");
else dst_buf[dst_index++] = user_supplied_string[i];
dst_buf[dst_index++] = ';';
/* encode to < */

The programmer attempts to encode the ampersand character in the user-controlled string, however the length of the string is validated before the encoding procedure is applied. Furthermore, the programmer assumes encoding expansion will only expand a given character by a factor of 4, while the encoding of the ampersand expands by 5. As a result, when the encoding procedure expands the string it is possible to overflow the destination buffer if the attacker provides a string of many ampersands.

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-119

The following example asks a user for an offset into an array to select an item.


               
}
printf("You selected %s\n", items[index-1]);

The programmer allows the user to specify which element in the list to select, however an attacker can provide an out-of-bounds offset, resulting in a buffer over-read (CWE-126).

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-119

In the following code, the method retrieves a value from an array at a specific array index location that is given as an input parameter to the method


               
}
return value;// check that the array index is less than the maximum// length of the array
value = array[index];// get the value at the specified index of the array
// if array index is invalid then output error message// and return value indicating error
value = -1;

However, this method only verifies that the given array index is less than the maximum length of the array but does not check for the minimum value (CWE-839). This will allow a negative value to be accepted as the input array index, which will result in a out of bounds read (CWE-125) and may allow access to sensitive memory. The input array index should be checked to verify that is within the maximum and minimum range required for the array (CWE-129). In this example the if statement should be modified to include a minimum range check, as shown below.


               
...// check that the array index is within the correct// range of values for the array

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-119

Windows provides the _mbs family of functions to perform various operations on multibyte strings. When these functions are passed a malformed multibyte string, such as a string containing a valid leading byte followed by a single null byte, they can read or write past the end of the string buffer causing a buffer overflow. The following functions all pose a risk of buffer overflow: _mbsinc _mbsdec _mbsncat _mbsncpy _mbsnextc _mbsnset _mbsrev _mbsset _mbsstr _mbstok _mbccpy _mbslen

Overview

Type

Cisco IOS

First reported 7 years ago

2017-07-17 21:29:00

Last updated 5 years ago

2019-10-09 23:28:00

Affected Software

Cisco IOS 12.2 (33)SXI

12.2\(33\)sxi

Cisco IOS 12.2 (33)SXI1

12.2\(33\)sxi1

Cisco IOS 12.2(50)SE

12.2\(50\)se

Cisco IOS 12.2(50)SE1

12.2\(50\)se1

Cisco IOS 12.2(50)SE2

12.2\(50\)se2

Cisco IOS 12.2(50)SE3

12.2\(50\)se3

Cisco IOS 12.2(50)SE4

12.2\(50\)se4

Cisco IOS 12.2(50)SE5

12.2\(50\)se5

Cisco IOS 12.2(50)SG

12.2\(50\)sg

Cisco IOS 12.2(50)SG1

12.2\(50\)sg1

Cisco IOS 12.2(50)SG2

12.2\(50\)sg2

Cisco IOS 12.2(50)SG3

12.2\(50\)sg3

Cisco IOS 12.2(50)SG4

12.2\(50\)sg4

Cisco IOS 12.2(50)SG5

12.2\(50\)sg5

Cisco IOS 12.2(50)SG6

12.2\(50\)sg6

Cisco IOS 12.2(50)SG7

12.2\(50\)sg7

Cisco IOS 12.2(50)SG8

12.2\(50\)sg8

Cisco IOS 12.2(50)SQ

12.2\(50\)sq

Cisco IOS 12.2(50)SQ1

12.2\(50\)sq1

Cisco IOS 12.2(50)SQ2

12.2\(50\)sq2

Cisco IOS 12.2(50)SQ3

12.2\(50\)sq3

Cisco IOS 12.2(50)SQ4

12.2\(50\)sq4

Cisco IOS 12.2(50)SQ5

12.2\(50\)sq5

Cisco IOS 12.2(50)SQ6

12.2\(50\)sq6

Cisco IOS 12.2(50)SQ7

12.2\(50\)sq7

Cisco IOS 12.2(52)EX

12.2\(52\)ex

Cisco IOS 12.2(52)EX1

12.2\(52\)ex1

Cisco IOS 12.2(52)EY

12.2\(52\)ey

Cisco IOS 12.2(52)EY1

12.2\(52\)ey1

Cisco IOS 12.2(52)EY1B

12.2\(52\)ey1b

Cisco IOS 12.2(52)EY1C

12.2\(52\)ey1c

Cisco IOS 12.2(52)EY2

12.2\(52\)ey2

Cisco IOS 12.2(52)EY2A

12.2\(52\)ey2a

Cisco IOS 12.2(52)EY3

12.2\(52\)ey3

Cisco IOS 12.2(52)EY3A

12.2\(52\)ey3a

Cisco IOS 12.2(52)EY4

12.2\(52\)ey4

Cisco IOS 12.2 (52)SE

12.2\(52\)se

Cisco IOS 12.2 (52)SE1

12.2\(52\)se1

Cisco IOS 12.2(52)SG

12.2\(52\)sg

Cisco IOS 12.2(52)XO

12.2\(52\)xo

Cisco IOS 12.2(53)EX

12.2\(53\)ex

Cisco IOS 12.2(53)EY

12.2\(53\)ey

Cisco IOS 12.2(53)EZ

12.2\(53\)ez

Cisco IOS 12.2(53)SE

12.2\(53\)se

Cisco IOS 12.2(53)SE1

12.2\(53\)se1

Cisco IOS 12.2(53)SE2

12.2\(53\)se2

Cisco IOS 12.2(53)SG

12.2\(53\)sg

Cisco IOS 12.2(53)SG1

12.2\(53\)sg1

Cisco IOS 12.2(53)SG2

12.2\(53\)sg2

Cisco IOS 12.2(53)SG3

12.2\(53\)sg3

Cisco IOS 12.2(53)SG4

12.2\(53\)sg4

Cisco IOS 12.2(53)SG5

12.2\(53\)sg5

Cisco IOS 12.2(53)SG6

12.2\(53\)sg6

Cisco IOS 12.2(53)SG7

12.2\(53\)sg7

Cisco IOS 12.2(53)SG8

12.2\(53\)sg8

Cisco IOS 12.2(53)SG9

12.2\(53\)sg9

Cisco IOS 12.2(53)SG10

12.2\(53\)sg10

Cisco IOS 12.2(53)SG11

12.2\(53\)sg11

Cisco IOS 12.2(54)SE

12.2\(54\)se

Cisco IOS 12.2(54)SG

12.2\(54\)sg

Cisco IOS 12.2(54)SG1

12.2\(54\)sg1

Cisco IOS 12.2(54)WO

12.2\(54\)wo

Cisco IOS 12.2(54)XO

12.2\(54\)xo

Cisco IOS 12.2(55)EX

12.2\(55\)ex

Cisco IOS 12.2(55)EX1

12.2\(55\)ex1

Cisco IOS 12.2(55)EX2

12.2\(55\)ex2

Cisco IOS 12.2(55)EX3

12.2\(55\)ex3

Cisco IOS 12.2(55)EY

12.2\(55\)ey

Cisco IOS 12.2(55)EZ

12.2\(55\)ez

Cisco IOS 12.2(55)SE

12.2\(55\)se

Cisco IOS 12.2(55)SE1

12.2\(55\)se1

Cisco IOS 12.2(55)SE2

12.2\(55\)se2

Cisco IOS 12.2(55)SE3

12.2\(55\)se3

Cisco IOS 12.2(55)SE4

12.2\(55\)se4

Cisco IOS 12.2(55)SE5

12.2\(55\)se5

Cisco IOS 12.2(55)SE6

12.2\(55\)se6

Cisco IOS 12.2(55)SE7

12.2\(55\)se7

Cisco IOS 12.2(55)SE8

12.2\(55\)se8

Cisco IOS 12.2(55)SE9

12.2\(55\)se9

Cisco IOS 12.2(55)SE10

12.2\(55\)se10

Cisco IOS 12.2(55)SE11

12.2\(55\)se11

Cisco IOS 12.2(58)EX

12.2\(58\)ex

Cisco IOS 12.2(58)EY

12.2\(58\)ey

Cisco IOS 12.2(58)EY1

12.2\(58\)ey1

Cisco IOS 12.2(58)EY2

12.2\(58\)ey2

Cisco IOS 12.2(58)EZ

12.2\(58\)ez

Cisco IOS 12.2(58)SE

12.2\(58\)se

Cisco IOS 12.2(58)SE1

12.2\(58\)se1

Cisco IOS 12.2(58)SE2

12.2\(58\)se2

Cisco IOS 12.2(60)EZ

12.2\(60\)ez

Cisco IOS 12.2(60)EZ1

12.2\(60\)ez1

Cisco IOS 12.2(60)EZ2

12.2\(60\)ez2

Cisco IOS 12.2(60)EZ3

12.2\(60\)ez3

Cisco IOS 12.2(60)EZ4

12.2\(60\)ez4

Cisco IOS 12.2(60)EZ5

12.2\(60\)ez5

Cisco IOS 12.2(60)EZ6

12.2\(60\)ez6

Cisco IOS 12.2(60)EZ7

12.2\(60\)ez7

Cisco IOS 12.2(60)EZ8

12.2\(60\)ez8

Cisco IOS 12.2(60)EZ9

12.2\(60\)ez9

Cisco IOS 12.2(60)EZ10

12.2\(60\)ez10

Cisco IOS 12.2(60)EZ11

12.2\(60\)ez11

Cisco IOS 15.0(1)EX

15.0\(1\)ex

Cisco IOS 15.0(1)EY

15.0\(1\)ey

Cisco IOS 15.0(1)EY1

15.0\(1\)ey1

Cisco IOS 15.0(1)EY2

15.0\(1\)ey2

Cisco IOS 15.0 (1)SE

15.0\(1\)se

Cisco IOS 15.0(1)SE1

15.0\(1\)se1

Cisco IOS 15.0(1)SE2

15.0\(1\)se2

Cisco IOS 15.0(1)SE3

15.0\(1\)se3

Cisco IOS 15.0(1)XO

15.0\(1\)xo

Cisco IOS 15.0(1)XO1

15.0\(1\)xo1

Cisco IOS 15.0(2)EA1

15.0\(2\)ea1

Cisco IOS 15.0(2)EB

15.0\(2\)eb

Cisco IOS 15.0(2)EC

15.0\(2\)ec

Cisco IOS 15.0(2)ED

15.0\(2\)ed

Cisco IOS 15.0(2)ED1

15.0\(2\)ed1

Cisco IOS 15.0(2)EH

15.0\(2\)eh

Cisco IOS 15.0(2)EJ

15.0\(2\)ej

Cisco IOS 15.0(2)EJ1

15.0\(2\)ej1

Cisco IOS 15.0(2)EK

15.0\(2\)ek

Cisco IOS 15.0(2)EK1

15.0\(2\)ek1

Cisco IOS 15.0(2)EX

15.0\(2\)ex

Cisco IOS 15.0(2)EX1

15.0\(2\)ex1

Cisco IOS 15.0(2)EX2

15.0\(2\)ex2

Cisco IOS 15.0(2)EX3

15.0\(2\)ex3

Cisco IOS 15.0(2)EX4

15.0\(2\)ex4

Cisco IOS 15.0(2)EX5

15.0\(2\)ex5

Cisco IOS 15.0(2)EX8

15.0\(2\)ex8

Cisco IOS 15.0(2)EX10

15.0\(2\)ex10

Cisco IOS 15.0(2)EY

15.0\(2\)ey

Cisco IOS 15.0(2)EY1

15.0\(2\)ey1

Cisco IOS 15.0(2)EY2

15.0\(2\)ey2

Cisco IOS 15.0(2)EY3

15.0\(2\)ey3

Cisco IOS 15.0(2)EZ

15.0\(2\)ez

Cisco IOS 15.0(2)SE

15.0\(2\)se

Cisco IOS 15.0(2)SE1

15.0\(2\)se1

Cisco IOS 15.0(2)SE2

15.0\(2\)se2

Cisco IOS 15.0(2)SE3

15.0\(2\)se3

Cisco IOS 15.0(2)SE4

15.0\(2\)se4

Cisco IOS 15.0(2)SE5

15.0\(2\)se5

Cisco IOS 15.0(2)SE6

15.0\(2\)se6

Cisco IOS 15.0(2)SE7

15.0\(2\)se7

Cisco IOS 15.0(2)SE9

15.0\(2\)se9

Cisco IOS 15.0(2)SE10

15.0\(2\)se10

Cisco IOS 15.0(2)SE10A

15.0\(2\)se10a

Cisco IOS 15.0(2)SG

15.0\(2\)sg

Cisco IOS 15.0(2)SG1

15.0\(2\)sg1

Cisco IOS 15.0(2)SG2

15.0\(2\)sg2

Cisco IOS 15.0(2)SG3

15.0\(2\)sg3

Cisco IOS 15.0(2)SG4

15.0\(2\)sg4

Cisco IOS 15.0(2)SG5

15.0\(2\)sg5

Cisco IOS 15.0(2)SG6

15.0\(2\)sg6

Cisco IOS 15.0(2)SG7

15.0\(2\)sg7

Cisco IOS 15.0(2)SG8

15.0\(2\)sg8

Cisco IOS 15.0(2)SG9

15.0\(2\)sg9

Cisco IOS 15.0(2)SG10

15.0\(2\)sg10

Cisco IOS 15.0(2)SG11

15.0\(2\)sg11

Cisco IOS 15.0(2)SQD

15.0\(2\)sqd

Cisco IOS 15.0(2)SQD1

15.0\(2\)sqd1

Cisco IOS 15.0(2)SQD2

15.0\(2\)sqd2

Cisco IOS 15.0(2)SQD5

15.0\(2\)sqd5

Cisco IOS 15.0(2)SQD6

15.0\(2\)sqd6

Cisco IOS 15.0(2)XO

15.0\(2\)xo

Cisco IOS 15.0(2a)EX5

15.0\(2a\)ex5

Cisco IOS 15.0(2A)SE9

15.0\(2a\)se9

Cisco IOS 15.1(1)SG

15.1\(1\)sg

Cisco IOS 15.1(1)SG1

15.1\(1\)sg1

Cisco IOS 15.1(1)SG2

15.1\(1\)sg2

Cisco IOS 15.1(2)SG

15.1\(2\)sg

Cisco IOS 15.1(2)SG1

15.1\(2\)sg1

Cisco IOS 15.1(2)SG2

15.1\(2\)sg2

Cisco IOS 15.1(2)SG3

15.1\(2\)sg3

Cisco IOS 15.1(2)SG4

15.1\(2\)sg4

Cisco IOS 15.1(2)SG5

15.1\(2\)sg5

Cisco IOS 15.1(2)SG6

15.1\(2\)sg6

Cisco IOS 15.1(2)SG7

15.1\(2\)sg7

Cisco IOS 15.1(2)SG8

15.1\(2\)sg8

Cisco IOS 15.2(1)E

15.2\(1\)e

Cisco IOS 15.2(1)E1

15.2\(1\)e1

Cisco IOS 15.2(1)E2

15.2\(1\)e2

Cisco IOS 15.2(1)E3

15.2\(1\)e3

Cisco IOS 15.2(1)EY

15.2\(1\)ey

Cisco IOS 15.2(1)SY

15.2\(1\)sy

Cisco IOS 15.2(1)SY0A

15.2\(1\)sy0a

Cisco IOS 15.2(1)SY1

15.2\(1\)sy1

Cisco IOS 15.2(1)SY1A

15.2\(1\)sy1a

Cisco IOS 15.2(1)SY2

15.2\(1\)sy2

Cisco IOS 15.2(1)SY3

15.2\(1\)sy3

Cisco IOS 15.2(1)SY4

15.2\(1\)sy4

Cisco IOS 15.2(2)E

15.2\(2\)e

Cisco IOS 15.2(2)E1

15.2\(2\)e1

Cisco IOS 15.2(2)E2

15.2\(2\)e2

Cisco IOS 15.2(2)E3

15.2\(2\)e3

Cisco IOS 15.2(2)E4

15.2\(2\)e4

Cisco IOS 15.2(2)E5

15.2\(2\)e5

Cisco IOS 15.2(2)E5A

15.2\(2\)e5a

Cisco IOS 15.2(2)EA2

15.2\(2\)ea2

Cisco IOS 15.2(2)EA3

15.2\(2\)ea3

Cisco IOS 15.2(2)EB2

15.2\(2\)eb2

Cisco IOS 15.2(2)GC

15.2\(2\)gc

Cisco IOS 15.2(2)SY

15.2\(2\)sy

Cisco IOS 15.2(2)SY1

15.2\(2\)sy1

Cisco IOS 15.2(2)SY2

15.2\(2\)sy2

Cisco IOS 15.2(2)T

15.2\(2\)t

Cisco IOS 15.2(2)T1

15.2\(2\)t1

Cisco IOS 15.2(2)T2

15.2\(2\)t2

Cisco IOS 15.2(2)T3

15.2\(2\)t3

Cisco IOS 15.2(2)T4

15.2\(2\)t4

Cisco IOS 15.2(2a)E1

15.2\(2a\)e1

Cisco IOS 15.2(3)E

15.2\(3\)e

Cisco IOS 15.2(3)E1

15.2\(3\)e1

Cisco IOS 15.2(3)E3

15.2\(3\)e3

Cisco IOS 15.2(3)EA

15.2\(3\)ea

Cisco IOS 15.2(3)GC

15.2\(3\)gc

Cisco IOS 15.2(3)GC1

15.2\(3\)gc1

Cisco IOS 15.2(3)T

15.2\(3\)t

Cisco IOS 15.2(3a)E

15.2\(3a\)e

Cisco IOS 15.2(4)E

15.2\(4\)e

Cisco IOS 15.2(4)E1

15.2\(4\)e1

Cisco IOS 15.2(4)E3

15.2\(4\)e3

Cisco IOS 15.2(4)E4

15.2\(4\)e4

Cisco IOS 15.2(4)EA

15.2\(4\)ea

Cisco IOS 15.2(4)EA1

15.2\(4\)ea1

Cisco IOS 15.2(4)EA3

15.2\(4\)ea3

Cisco IOS 15.2(4)EA4

15.2\(4\)ea4

Cisco IOS 15.2(4)EC1

15.2\(4\)ec1

Cisco IOS 15.2(4)GC

15.2\(4\)gc

Cisco IOS 15.2(4)GC1

15.2\(4\)gc1

Cisco IOS 15.2(4)GC2

15.2\(4\)gc2

Cisco IOS 15.2(4)GC3

15.2\(4\)gc3

Cisco IOS 15.2(4)M

15.2\(4\)m

Cisco IOS 15.2(4)M1

15.2\(4\)m1

Cisco IOS 15.2(4)M2

15.2\(4\)m2

Cisco IOS 15.2(4)M3

15.2\(4\)m3

Cisco IOS 15.2(4)M4

15.2\(4\)m4

Cisco IOS 15.2(4)M5

15.2\(4\)m5

Cisco IOS 15.2(4)M6

15.2\(4\)m6

Cisco IOS 15.2(4)M6A

15.2\(4\)m6a

Cisco IOS 15.2(4)M7

15.2\(4\)m7

Cisco IOS 15.2(4)M8

15.2\(4\)m8

Cisco IOS 15.2(4)M9

15.2\(4\)m9

Cisco IOS 15.2(4)M10

15.2\(4\)m10

Cisco IOS 15.2(4)M11

15.2\(4\)m11

Cisco IOS 15.2(4M)E1

15.2\(4m\)e1

Cisco IOS 15.2(4M)E3

15.2\(4m\)e3

Cisco IOS 15.2(4P)E1

15.2\(4p\)e1

Cisco IOS 15.2(5)E1

15.2\(5\)e1

Cisco IOS 15.2(5)E2

15.2\(5\)e2

Cisco IOS 15.2(5)E2A

15.2\(5\)e2a

Cisco IOS 15.2(5)EA

15.2\(5\)ea

Cisco IOS 15.2(5)EX

15.2\(5\)ex

Cisco IOS 15.2(5a)E

15.2\(5a\)e

Cisco IOS 15.2(5A)E1

15.2\(5a\)e1

Cisco IOS 15.2(5b)E

15.2\(5b\)e

Cisco IOS 15.2(5C)E

15.2\(5c\)e

Cisco IOS 15.3(1)SY

15.3\(1\)sy

Cisco IOS 15.3(1)SY2

15.3\(1\)sy2

Cisco IOS 15.3(1)T

15.3\(1\)t

Cisco IOS 15.3(1)T1

15.3\(1\)t1

Cisco IOS 15.3(1)T2

15.3\(1\)t2

Cisco IOS 15.3(1)T3

15.3\(1\)t3

Cisco IOS 15.3(1)T4

15.3\(1\)t4

Cisco IOS 15.3(2)T

15.3\(2\)t

Cisco IOS 15.3(2)T1

15.3\(2\)t1

Cisco IOS 15.3(2)T2

15.3\(2\)t2

Cisco IOS 15.3(2)T3

15.3\(2\)t3

Cisco IOS 15.3(2)T4

15.3\(2\)t4

Cisco IOS 15.3(3)M

15.3\(3\)m

Cisco IOS 15.3(3)M1

15.3\(3\)m1

Cisco IOS 15.3(3)M2

15.3\(3\)m2

Cisco IOS 15.3(3)M3

15.3\(3\)m3

Cisco IOS 15.3(3)M4

15.3\(3\)m4

Cisco IOS 15.3(3)M5

15.3\(3\)m5

Cisco IOS 15.3(3)M6

15.3\(3\)m6

Cisco IOS 15.3(3)M7

15.3\(3\)m7

Cisco IOS 15.3(3)M9

15.3\(3\)m9

Cisco IOS 15.4(1)CG

15.4\(1\)cg

Cisco IOS 15.4(1)CG1

15.4\(1\)cg1

Cisco IOS 15.4(1)SY

15.4\(1\)sy

Cisco IOS 15.4(1)SY1

15.4\(1\)sy1

Cisco IOS 15.4(1)SY2

15.4\(1\)sy2

Cisco IOS 15.4(1)t

15.4\(1\)t

Cisco IOS 15.4(1)T1

15.4\(1\)t1

Cisco IOS 15.4(1)T2

15.4\(1\)t2

Cisco IOS 15.4(1)T3

15.4\(1\)t3

Cisco IOS 15.4(1)T4

15.4\(1\)t4

Cisco IOS 15.4(2)T

15.4\(2\)t

Cisco IOS 15.4(2)T1

15.4\(2\)t1

Cisco IOS 15.4(2)T2

15.4\(2\)t2

Cisco IOS 15.4(2)T3

15.4\(2\)t3

Cisco IOS 15.4(2)T4

15.4\(2\)t4

Cisco IOS 15.4(3)M

15.4\(3\)m

Cisco IOS 15.4(3)M1

15.4\(3\)m1

Cisco IOS 15.4(3)M2

15.4\(3\)m2

Cisco IOS 15.4(3)M3

15.4\(3\)m3

Cisco IOS 15.4(3)M4

15.4\(3\)m4

Cisco IOS 15.4(3)M5

15.4\(3\)m5

Cisco IOS 15.4(3)M6

15.4\(3\)m6

Cisco IOS 15.4(3)M7

15.4\(3\)m7

Cisco IOS 15.5(1)SY

15.5\(1\)sy

Cisco IOS 15.5(1)T

15.5\(1\)t

Cisco IOS 15.5(1)T1

15.5\(1\)t1

Cisco IOS 15.5(1)T2

15.5\(1\)t2

Cisco IOS 15.5(1)T3

15.5\(1\)t3

Cisco IOS 15.5(1)T4

15.5\(1\)t4

Cisco IOS 15.5(2)T

15.5\(2\)t

Cisco IOS 15.5(2)T1

15.5\(2\)t1

Cisco IOS 15.5(2)T2

15.5\(2\)t2

Cisco IOS 15.5(2)T3

15.5\(2\)t3

Cisco IOS 15.5(2)T4

15.5\(2\)t4

Cisco IOS 15.5(3)M0A

15.5\(3\)m0a

Cisco IOS 15.5(3)m1

15.5\(3\)m1

Cisco IOS 15.5(3)M2

15.5\(3\)m2

Cisco IOS 15.5(3)M3

15.5\(3\)m3

Cisco IOS 15.5(3)M4

15.5\(3\)m4

Cisco IOS 15.5(3)M5

15.5\(3\)m5

Cisco IOS 15.5(3)M6

15.5\(3\)m6

Cisco IOS 15.6(1)t0a

15.6\(1\)t0a

Cisco IOS 15.6(3)M

15.6\(3\)m

Cisco IOS 15.6(3)M1b

15.6\(3\)m1b

Cisco IOS 15.6(3)M2

15.6\(3\)m2

Cisco IOS 15.6(3)M2A

15.6\(3\)m2a

Cisco IOS 15.6(3)M3

15.6\(3\)m3

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.