PT-2022-3843 · Net Snmp+8 · Net-Snmp+8

Nanyu Zhong

+1

·

Published

2022-02-25

·

Updated

2025-01-17

·

CVE-2022-24807

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions net-snmp versions prior to 5.9.2
Description The issue is related to a malformed OID in a SET request to SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable, which can cause an out-of-bounds memory access. A user with read-write credentials can exploit this issue.
Recommendations For versions prior to 5.9.2, update to version 5.9.2 or later. As a temporary workaround, consider using strong SNMPv3 credentials and avoid sharing the credentials. For those who must use SNMPv1 or SNMPv2c, use a complex community string and enhance the protection by restricting access to a given IP address range.

Exploit

Fix

SQL injection

RCE

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2024:7260
BDU:2022-04637
BDU:2022-04644
CVE-2022-24807
DLA-3088-1
DSA-5209-1
INFSA-2024_7260
MGASA-2022-0311
OESA-2022-1888
OPENSUSE-SU-2022_4205-1
OPENSUSE-SU-2024:12174-1
RHSA-2024:7260
RHSA-2024:7875
RHSA-2024_7260
RLSA-2024:7260
SUSE-RU-2024:0029-1
SUSE-SU-2022:4205-1
SUSE-SU-2022:4205-2
USN-5543-1
USN-5795-2

Affected Products

Almalinux
Astra Linux
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Net-Snmp