NULL Pointer Dereference Vulnerability in net-snmp Prior to 5.9.2
CVE-2022-24810

8.8HIGH

Key Information:

Vendor

Net-snmp

Status
Vendor
CVE Published:
16 April 2024

What is CVE-2022-24810?

Net-SNMP utilizes various tools associated with the Simple Network Management Protocol (SNMP). Prior to version 5.9.2, there exists a vulnerability that allows a user with read-write credentials to exploit a malformed Object Identifier (OID) when performing a SET operation on the nsVacmAccessTable. This exploitation can lead to a NULL pointer dereference, resulting in potential disruptions of service. To mitigate risks, it is imperative for users to adopt robust SNMPv3 credentials and refrain from sharing them. If SNMPv1 or SNMPv2c is necessary, users should opt for complex community strings and further reinforce security by restricting access to designated IP address ranges.

Affected Version(s)

net-snmp 0 < 5.9.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.