PT-2020-18901 · Minisnmpd · Minisnmpd
Published
2020-02-04
·
Updated
2022-06-07
·
CVE-2020-6060
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
MiniSNMPD version 1.4
Description
A stack buffer overflow issue exists in the way MiniSNMPD handles multiple connections. This can be triggered by a specially timed sequence of SNMP connections, resulting in a denial of service. An attacker can exploit this by initiating multiple connections to the server.
Recommendations
For MiniSNMPD version 1.4, consider restricting the number of concurrent connections to the server as a temporary workaround until a patch is available. Additionally, monitor server resources closely to quickly identify and respond to potential denial of service attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Minisnmpd