PT-2020-18901 · Minisnmpd · Minisnmpd

Published

2020-02-04

·

Updated

2022-06-07

·

CVE-2020-6060

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MiniSNMPD version 1.4
Description A stack buffer overflow issue exists in the way MiniSNMPD handles multiple connections. This can be triggered by a specially timed sequence of SNMP connections, resulting in a denial of service. An attacker can exploit this by initiating multiple connections to the server.
Recommendations For MiniSNMPD version 1.4, consider restricting the number of concurrent connections to the server as a temporary workaround until a patch is available. Additionally, monitor server resources closely to quickly identify and respond to potential denial of service attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6060

Affected Products

Minisnmpd