SNMPv1 and SNMPv2c Vulnerabilities in Master Agent and Subagent
CVE-2022-24806

5.3MEDIUM

Key Information:

Vendor

Net-snmp

Status
Vendor
CVE Published:
16 April 2024

What is CVE-2022-24806?

An Improper Input Validation vulnerability exists in Net-SNMP, which allows attackers to exploit devices with read-write credentials by sending malformed Object Identifiers (OIDs) to both the master agent and subagent simultaneously. This flaw can lead to unauthorized modifications or operations within the network management context. To mitigate risks, users are advised to upgrade to version 5.9.2 or later. It is recommended to use strong SNMPv3 credentials and limit access through appropriate IP address restrictions. For those relying on SNMPv1 or SNMPv2c, employing a complex community string is essential to enhance security.

Affected Version(s)

net-snmp 0 < 5.9.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.