Insecure File Permissions in Net-SNMP on OpenBSD
CVE-2015-8100

Currently unrated

Key Information:

Vendor

Net-snmp

Status
Vendor
CVE Published:
10 November 2015

What is CVE-2015-8100?

An information disclosure vulnerability exists in the Net-SNMP package within OpenBSD versions up to 5.8. The issue arises due to improper file permissions set on the snmpd.conf configuration file, which is assigned a mode of 0644. This configuration allows local users to read the file and potentially gain access to sensitive community information. It highlights the need for secure file permission practices to safeguard critical configuration data from unauthorized access.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.