PT-2022-7448 · Net Snmp+8 · Net-Snmp+8

Nanyu Zhong

+1

·

Published

2022-07-01

·

Updated

2025-01-17

·

CVE-2022-24808

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions net-snmp versions prior to 5.9.2
Description The issue is related to a NULL pointer dereference in the NET-SNMP-AGENT-MIB::nsLogTable function. A user with read-write credentials can use a malformed OID in a SET request to cause this issue. To mitigate the risk, users should use strong SNMPv3 credentials and avoid sharing them. For those who must use SNMPv1 or SNMPv2c, using a complex community string and restricting access to a given IP address range can enhance protection.
Recommendations To resolve the issue, update to version 5.9.2 or later. As a temporary workaround, consider restricting access to the NET-SNMP-AGENT-MIB::nsLogTable function until a patch is applied. Use strong SNMPv3 credentials and avoid sharing them. For SNMPv1 or SNMPv2c, use a complex community string and restrict access to a given IP address range.

Exploit

Fix

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALSA-2024:7260
BDU:2024-06507
CVE-2022-24808
DLA-3088-1
DSA-5209-1
INFSA-2024_7260
MGASA-2022-0311
OESA-2022-1888
OPENSUSE-SU-2022_4205-1
OPENSUSE-SU-2024:12174-1
RHSA-2024:7260
RHSA-2024:7875
RHSA-2024_7260
RLSA-2024:7260
SUSE-RU-2024:0029-1
SUSE-SU-2022:4205-1
SUSE-SU-2022:4205-2
USN-5543-1
USN-5795-2

Affected Products

Almalinux
Astra Linux
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Net-Snmp