SNMPv1 and SNMPv2c Vulnerabilities in Master Agent and Subagent
CVE-2022-24806
5.3MEDIUM
What is CVE-2022-24806?
An Improper Input Validation vulnerability exists in Net-SNMP, which allows attackers to exploit devices with read-write credentials by sending malformed Object Identifiers (OIDs) to both the master agent and subagent simultaneously. This flaw can lead to unauthorized modifications or operations within the network management context. To mitigate risks, users are advised to upgrade to version 5.9.2 or later. It is recommended to use strong SNMPv3 credentials and limit access through appropriate IP address restrictions. For those relying on SNMPv1 or SNMPv2c, employing a complex community string is essential to enhance security.
Affected Version(s)
net-snmp 0 < 5.9.2
