Lucene search

K
cve[email protected]CVE-2015-5621
HistoryAug 19, 2015 - 3:59 p.m.

CVE-2015-5621

2015-08-1915:59:09
CWE-19
web.nvd.nist.gov
112
cve-2015-5621
snmp
net-snmp
denial of service
remote attack
code execution
vulnerability
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.1 High

AI Score

Confidence

High

0.082 Low

EPSS

Percentile

94.4%

The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.

Affected configurations

NVD
Node
net-snmpnet-snmpRange5.7.2
CPENameOperatorVersion
net-snmp:net-snmpnet-snmple5.7.2

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.1 High

AI Score

Confidence

High

0.082 Low

EPSS

Percentile

94.4%