NULL Pointer Dereference Vulnerability in net-snmp Prior to 5.9.2
CVE-2022-24810
8.8HIGH
What is CVE-2022-24810?
Net-SNMP utilizes various tools associated with the Simple Network Management Protocol (SNMP). Prior to version 5.9.2, there exists a vulnerability that allows a user with read-write credentials to exploit a malformed Object Identifier (OID) when performing a SET operation on the nsVacmAccessTable. This exploitation can lead to a NULL pointer dereference, resulting in potential disruptions of service. To mitigate risks, it is imperative for users to adopt robust SNMPv3 credentials and refrain from sharing them. If SNMPv1 or SNMPv2c is necessary, users should opt for complex community strings and further reinforce security by restricting access to designated IP address ranges.
Affected Version(s)
net-snmp 0 < 5.9.2
