Denial of Service Vulnerability in net-snmp by Net-SNMP
CVE-2015-5621
7.5HIGH
Key Information:
Badges
๐พ Exploit Exists๐ฃ EPSS 40%
What is CVE-2015-5621?
The snmp_pdu_parse function in net-snmp versions up to 5.7.2 is susceptible to a vulnerability that fails to properly handle varBind variables when parsing SNMP PDUs. This flaw can be exploited by remote attackers to trigger a denial of service condition, potentially leading to application crashes or even the execution of arbitrary code through specially crafted SNMP packets.
References
EPSS Score
40% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
