Lucene search

K
f5F5F5:K17315
HistorySep 29, 2015 - 12:00 a.m.

K17315 : SNMP vulnerability CVE-2014-3565

2015-09-2900:00:00
my.f5.com
63

8 High

AI Score

Confidence

High

0.067 Low

EPSS

Percentile

93.9%

Security Advisory Description

snmplib/mib.c in net-snmp 5.7.0 and earlier, when the -OQ option is used, allows remote attackers to cause a denial of service (snmptrapd crash) via a crafted SNMP trap message, which triggers a conversion to the variable type designated in the MIB file, as demonstrated by a NULL type in an ifMtu trap message.
(
CVE-2014-3565
)
Impact
The snmpdtrapdprocess may stop responding if a specially crafted SNMP trap is received. BIG-IP, Enterprise Manager, and BIG-IQ systems do not use the included snmptrapdbinary in any supported configuration. On Traffix systems, the management station will be unable to search the splunk database for traps that occurred while snmptrapdwas down.