7.8
CVE-2020-15862
- EPSS 0.38%
- Veröffentlicht 20.08.2020 01:17:13
- Zuletzt bearbeitet 21.11.2024 05:06:19
- Erkennungen
Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
Netapp ≫ Cloud Backup Version -
Netapp ≫ Hci Management Node Version -
Netapp ≫ Smi-s Provider Version -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.38% | 0.299 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
https://security.gentoo.org/glsa/202008-12
https://security.netapp.com/advisory/ntap-20200904-0001/
https://usn.ubuntu.com/4471-1/
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=965166
https://github.com/net-snmp/net-snmp/commit/77f6c60f57dba0aaea5d8ef1dd94bcd0c8e6d205
https://salsa.debian.org/debian/net-snmp/-/commit/fad8725402752746daf0a751dcff19eb6aeab52e
https://security-tracker.debian.org/tracker/CVE-2020-15862