CVE-2017-3881
ENISA EUVD: EUVD-2017-12998 ↗
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
4 articles
EPSS Score
Source: FIRST.org · 2026-05-24
94.28%
probability
This CVE has a 94.28% probability
of being exploited in the next 30 days.
0%
Top 99.9th percentile of all CVEs
100%
CVSS v3.1
Source: NVD9.8
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Project ZeroBuffer overflow in IOS Cluster Management Protocol
Affected Products
Google Project Zero
Patched
March 17, 2017
Reported by
Vault 7 Disclosure
Root Cause Analysis
???
Exploits & PoC
artkond/cisco-rce
CVE-2017-3881 Cisco Catalyst Remote Code Execution PoC
213
homjxi0e/CVE-2017-3881-exploit-cisco-
PoC CVE-2017-3881 — homjxi0e/CVE-2017-3881-exploit-cisco-
2
1337g/CVE-2017-3881
credit to artkond
2
mzakyz666/PoC-CVE-2017-3881
Cisco Catalyst Remote Code Execution PoC
1
homjxi0e/CVE-2017-3881-Cisco
PoC CVE-2017-3881 — homjxi0e/CVE-2017-3881-Cisco
0
5 repos — triés par ⭐
Rechercher sur GitHub ↗
Cisco's Investigation into Vault 7 Leak Uncovers 0-Day Affecting 318 Products
BleepingComputer
Mar 20, 2017
Disable TELNET! Cisco finds 0-Day in CIA Dump affecting over 300 Network Switch Models
TheHackerNews
Security Advisory 2017-006
CERT-EU
Mar 21, 2017
Signal Intelligence
Confidence
92%
EPSS
94.28%
CVSS v3.1
9.8
Mentions
4
Last Seen
Mar 21, 2017
CNA Information
Analyst Note
CVE-2017-3881 is a critical remote code execution vulnerability in Cisco IOS/IOS XE with CVSS 9.8, confirmed by Project Zero inclusion and CERT-EU security advisory. The unauthenticated remote attack vector and elevated privilege execution capability strongly support the confirmed status despite limited public documentation.
Threat Actors 6
Kinsing
apt_group
🇷🇺 RU
Infy
apt_group
Information theft and espionage
🇮🇷 IR
TeamTNT
apt_group
🇩🇪 DE
Red October
apt_group
🇷🇺 RU
Operation Red Signature
apt_group
Information theft and espionage
🇨🇳 CN
Mana Team
apt_group
🇨🇳 CN
Triage Info
Decided atMar 03, 2026