PT-2022-3843 · Net Snmp+8 · Net-Snmp+8
Nanyu Zhong
+1
·
Published
2022-02-25
·
Updated
2025-01-17
·
CVE-2022-24807
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
net-snmp versions prior to 5.9.2
Description
The issue is related to a malformed OID in a SET request to
SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable, which can cause an out-of-bounds memory access. A user with read-write credentials can exploit this issue.Recommendations
For versions prior to 5.9.2, update to version 5.9.2 or later.
As a temporary workaround, consider using strong SNMPv3 credentials and avoid sharing the credentials.
For those who must use SNMPv1 or SNMPv2c, use a complex community string and enhance the protection by restricting access to a given IP address range.
Exploit
Fix
SQL injection
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Almalinux
Astra Linux
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Net-Snmp