net-snmp: Out-of-bounds memory access vulnerability in SNMP-VIEW-BASED-ACM-MIB
CVE-2022-24807
6.5MEDIUM
What is CVE-2022-24807?
A vulnerability exists in the Net-SNMP tools related to an out-of-bounds memory access that can be triggered by a malformed Object Identifier (OID) in a SET request directed at the SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable. This issue is exploitable by users possessing read-write credentials, potentially leading to unauthorized access or system disruption. To mitigate this risk, it is recommended to upgrade to version 5.9.2 or higher, utilize strong SNMPv3 credentials, and avoid credential sharing. Additionally, for those who must use SNMPv1 or SNMPv2c, employing complex community strings and restricting access to specific IP address ranges is advised.
Affected Version(s)
net-snmp 0 < 5.9.2
