PT-2022-7447 · Net Snmp+8 · Net-Snmp+8

Nanyu Zhong

+1

·

Published

2022-07-01

·

Updated

2025-02-11

·

CVE-2022-24810

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions net-snmp versions prior to 5.9.2
Description The issue is related to a NULL pointer dereference in the nsVacmAccessTable component of the net-snmp software. This can be caused by a user with read-write credentials using a malformed OID in a SET to the nsVacmAccessTable. To protect against this, users should use strong SNMPv3 credentials and avoid sharing them. For those who must use SNMPv1 or SNMPv2c, using a complex community string and restricting access to a given IP address range can enhance protection.
Recommendations For versions prior to 5.9.2, update to version 5.9.2 or later to apply the patch. As a temporary workaround, consider restricting access to the nsVacmAccessTable component until the patch is applied. Use strong SNMPv3 credentials and avoid sharing them. For SNMPv1 or SNMPv2c, use a complex community string and restrict access to a given IP address range.

Exploit

Fix

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALSA-2024:7260
BDU:2024-06506
CVE-2022-24810
DLA-3088-1
DSA-5209-1
INFSA-2024_7260
MGASA-2022-0311
OESA-2022-1888
OPENSUSE-SU-2022_4205-1
OPENSUSE-SU-2024:12174-1
RHSA-2024:7260
RHSA-2024:7875
RHSA-2024_7260
RLSA-2024:7260
SUSE-RU-2024:0029-1
SUSE-SU-2022:4205-1
SUSE-SU-2022:4205-2
USN-5543-1
USN-5795-2

Affected Products

Almalinux
Astra Linux
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Net-Snmp