04-11-2025 10:23 AM - edited 04-11-2025 10:30 AM
hi,
in reading about CVE-2017-3881:
https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-20170317-cmp.html
I see it says: "Cisco has released software updates that address this vulnerability."
But nowhere in that webpage do I see which *version* of IOS contains the fix - how can I find that version number?
Also, how can I find the versions that *do* contain the vulnerability?
(Hopefully there's a more direct method than just using the Cisco software checker website?)
And am I to understand that there are TWO ways to address this CVE:
1) Install the software update, or
2) disable telnet/CMP/etc.
thanks,
js.
04-11-2025 01:58 PM
The Advisory shows the bug ID, while the Bug Search Tool shows Known Fixed Releases for CSCvd48893 (it appears that there are 193 fixed releases).
The Advisory also says “Disabling the Telnet protocol as an allowed protocol for incoming connections would eliminate the exploit vector.” Unless your network is an isolated lab environment, telnet should probably be disabled anyway. In production networks, telnet and ftp are just too vulnerable to eavesdropping.
04-11-2025 04:43 PM - edited 04-11-2025 04:52 PM
CMP is old tech. It is the predecessor of the 3750 stacking technology and none of IOS-XE uses this technology any more.
EDIT: Actually, I am wrong. CMP is currently in used and has been given a new "name": Horizontal Stacking. 3560CX-12PD, and Catalyst 1300 (still) use Horizontal Stacking.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide