net-snmp vulnerable to Improper Input Validation when SETing malformed OIDs in master agent and subagent simultaneously
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 6.5epss 1.1%
probabilidade de exploração
1.1%top 38% das CVEs
exploração observada
nãonenhuma fonte reporta
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can exploit an Improper Input Validation vulnerability when SETing malformed OIDs in master agent and subagent simultaneously. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and avoid sharing the credentials. Those who must use SNMPv1 or SNMPv2c should use a complex community string and enhance the protection by restricting access to a given IP address range.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Produtos afetados
net-snmp · net-snmpReferências
https://bugzilla.redhat.com/show_bug.cgi?id=2103225https://github.com/net-snmp/net-snmp/commit/ce66eb97c17aa9a48bc079be7b65895266fa6775https://lists.debian.org/debian-lts-announce/2022/08/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FX75KKGMO5XMV6JMQZF6KOG3JPFNQBY7/https://security.gentoo.org/glsa/202210-29https://www.debian.org/security/2022/dsa-5209