NULL Pointer Dereference Vulnerability in net-snmp Prior to 5.9.2
CVE-2022-24808

6.5MEDIUM

Key Information:

Vendor

Net-snmp

Status
Vendor
CVE Published:
16 April 2024

What is CVE-2022-24808?

A vulnerability in Net-SNMP allows users with read-write credentials to craft a malformed Object Identifier (OID) in a SET request targeting the NET-SNMP-AGENT-MIB::nsLogTable. This results in a null pointer dereference, which can potentially lead to application instability or crashing. To mitigate this vulnerability, upgrading to version 5.9.2 or later is essential. It is also recommended to utilize strong SNMPv3 credentials and maintain strict access controls. For environments still using SNMPv1 or SNMPv2c, employing a complex community string and restricting device access to specific IP address ranges can enhance security.

Affected Version(s)

net-snmp 0 < 5.9.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.