net-snmp: Out-of-bounds memory access vulnerability in SNMP-VIEW-BASED-ACM-MIB
CVE-2022-24807

6.5MEDIUM

Key Information:

Vendor

Net-snmp

Status
Vendor
CVE Published:
16 April 2024

What is CVE-2022-24807?

A vulnerability exists in the Net-SNMP tools related to an out-of-bounds memory access that can be triggered by a malformed Object Identifier (OID) in a SET request directed at the SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable. This issue is exploitable by users possessing read-write credentials, potentially leading to unauthorized access or system disruption. To mitigate this risk, it is recommended to upgrade to version 5.9.2 or higher, utilize strong SNMPv3 credentials, and avoid credential sharing. Additionally, for those who must use SNMPv1 or SNMPv2c, employing complex community strings and restricting access to specific IP address ranges is advised.

Affected Version(s)

net-snmp 0 < 5.9.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.