vendor:
Net-SNMP
by:
Magnus
7.5
CVSS
HIGH
Remote Denial of Service
400
CWE
Product Name: Net-SNMP
Affected Version From: NET-SNMP 5.7.3
Affected Version To: NET-SNMP 5.7.3
Patch Exists: NO
Related CWE: N/A
CPE: a:net-snmp:net-snmp
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2018
NET-SNMP REMOTE DOS
A remotely exploitable vulnerability exists in NET-SNMP, which can be exploited with knowledge of the community string (in this case 'public') leading to Denial of Service. An attacker can send a maliciously crafted packet to the vulnerable system, resulting in a crash of the system.
Mitigation:
Ensure that the community string is not publicly known and is changed regularly. Additionally, ensure that the vulnerable system is not exposed to the public internet.