Privilege Escalation Vulnerability in Net-SNMP by Net-SNMP Project
CVE-2020-15861

7.8HIGH

Key Information:

Vendor

Net-snmp

Status
Vendor
CVE Published:
20 August 2020

What is CVE-2020-15861?

The vulnerability in Net-SNMP prior to version 5.7.4 arises from improper handling of UNIX symbolic links, allowing an attacker to exploit the symlink following to gain elevated privileges on the system. This flaw can potentially be leveraged to compromise the integrity and availability of systems that rely on Net-SNMP, emphasizing the importance of applying patches and updates to mitigate the risk.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.