PT-2001-1071 · Ucd · Ucd-Snmp-Utils+2

Published

2001-12-04

·

Updated

2018-10-12

·

CVE-2002-0013

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ucd-snmp versions 4.2.3 ucd-snmp-utils version 4.2.3 ucd-snmp-devel version 4.2.3
Description The issue concerns multiple vulnerabilities in SNMP implementations, which can be exploited remotely to disrupt the confidentiality, integrity, and availability of protected information. This can lead to a denial of service or privilege escalation via GetRequest, GetNextRequest, and SetRequest messages.
Recommendations For ucd-snmp version 4.2.3, consider disabling the SNMP service until a patch is available. For ucd-snmp-utils version 4.2.3, restrict access to the vulnerable utilities to minimize the risk of exploitation. For ucd-snmp-devel version 4.2.3, avoid using the affected development package until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-08242
BDU:2015-08243
BDU:2015-08244
CVE-2002-0013

Affected Products

Ucd-Snmp
Ucd-Snmp-Devel
Ucd-Snmp-Utils