NULL Pointer Dereference Vulnerability in net-snmp Prior to 5.9.2
CVE-2022-24808
6.5MEDIUM
What is CVE-2022-24808?
A vulnerability in Net-SNMP allows users with read-write credentials to craft a malformed Object Identifier (OID) in a SET request targeting the NET-SNMP-AGENT-MIB::nsLogTable. This results in a null pointer dereference, which can potentially lead to application instability or crashing. To mitigate this vulnerability, upgrading to version 5.9.2 or later is essential. It is also recommended to utilize strong SNMPv3 credentials and maintain strict access controls. For environments still using SNMPv1 or SNMPv2c, employing a complex community string and restricting device access to specific IP address ranges can enhance security.
Affected Version(s)
net-snmp 0 < 5.9.2
