5.3
CVE-2022-24806
- EPSS 1.05%
- Veröffentlicht 16.04.2024 20:15:08
- Zuletzt bearbeitet 17.01.2025 16:09:56
- Erkennungen
net-snmp vulnerable to Improper Input Validation when SETing malformed OIDs in master agent and subagent simultaneously
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can exploit an Improper Input Validation vulnerability when SETing malformed OIDs in master agent and subagent simultaneously. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and avoid sharing the credentials. Those who must use SNMPv1 or SNMPv2c should use a complex community string and enhance the protection by restricting access to a given IP address range.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedoraproject ≫ Fedora Version 35
Fedoraproject ≫ Fedora Version 36
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Redhat ≫ Enterprise Linux Version 9.0
Redhat ≫ Enterprise Linux Eus Version 9.2
Redhat ≫ Enterprise Linux Eus Version 9.4
Redhat ≫ Enterprise Linux For Arm 64 Version 9.0
Redhat ≫ Enterprise Linux For Arm 64 Version 9.2_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Version 9.4_aarch64
Redhat ≫ Enterprise Linux For Arm 64 Eus Version 9.4_aarch64
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 9.0
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 9.2_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 9.4_s390x
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 9.4_s390x
Redhat ≫ Enterprise Linux For Power Little Endian Version 9.0
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 9.2_ppc64le
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 9.4_ppc64le
Redhat ≫ Enterprise Linux Server Aus Version 9.2
Redhat ≫ Enterprise Linux Server Aus Version 9.4
Redhat ≫ Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions Version 9.2_ppc64le
Redhat ≫ Enterprise Linux Update Services For Sap Solutions Version 9.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.05% | 0.599 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.3 | 1.6 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
|
| security-advisories@github.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://bugzilla.redhat.com/show_bug.cgi?id=2103225
https://github.com/net-snmp/net-snmp/commit/ce66eb97c17aa9a48bc079be7b65895266fa6775
https://lists.debian.org/debian-lts-announce/2022/08/msg00020.html
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FX75KKGMO5XMV6JMQZF6KOG3JPFNQBY7/
https://security.gentoo.org/glsa/202210-29
https://www.debian.org/security/2022/dsa-5209