PT-2020-6262 · Snmptt+2 · Snmptt+2

Published

2020-08-16

·

Updated

2024-03-14

·

CVE-2020-24361

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SNMPTT versions prior to 1.4.2
Description The issue is related to incorrect remote user validation in the SNMPTT SNMP-trap handler. Exploitation of this issue may allow a remote attacker to access confidential data, compromise its integrity, and cause a denial of service. The vulnerability can be exploited by attackers to execute shell code via EXEC, PREXEC, or unknown trap exec.
Recommendations For SNMPTT versions prior to 1.4.2, update to version 1.4.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the EXEC, PREXEC, and unknown trap exec functions to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3129
ALT-PU-2020-3174
ALT-PU-2024-3798
BDU:2021-03734
CVE-2020-24361
DLA-2393-1

Affected Products

Alt Linux
Astra Linux
Snmptt