Description
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a SET to the nsVacmAccessTable to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and avoid sharing the credentials. Those who must use SNMPv1 or SNMPv2c should use a complex community string and enhance the protection by restricting access to a given IP address range.
Published: 2024-04-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-3088-1 net-snmp security update
Debian DSA Debian DSA DSA-5209-1 net-snmp security update
EUVD EUVD EUVD-2022-29610 net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a SET to the nsVacmAccessTable to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and avoid sharing the credentials. Those who must use SNMPv1 or SNMPv2c should use a complex community string and enhance the protection by restricting access to a given IP address range.
Ubuntu USN Ubuntu USN USN-5543-1 Net-SNMP vulnerabilities
Ubuntu USN Ubuntu USN USN-5795-2 Net-SNMP vulnerabilities
History

Mon, 10 Feb 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Debian
Debian debian Linux
Fedoraproject
Fedoraproject fedora
Net-snmp
Net-snmp net-snmp
CPEs cpe:2.3:a:net-snmp:net-snmp:*:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
Vendors & Products Debian
Debian debian Linux
Fedoraproject
Fedoraproject fedora
Net-snmp
Net-snmp net-snmp

Thu, 10 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Eus
CPEs cpe:/a:redhat:rhel_eus:9.2
Vendors & Products Redhat rhel Eus

Fri, 27 Sep 2024 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/a:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux

Subscriptions

Debian Debian Linux
Fedoraproject Fedora
Net-snmp Net-snmp
Redhat Enterprise Linux Rhel Eus
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-03T04:20:50.586Z

Reserved: 2022-02-10T16:41:34.918Z

Link: CVE-2022-24810

cve-icon Vulnrichment

Updated: 2024-08-03T04:20:50.586Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-16T20:15:09.227

Modified: 2025-02-11T21:56:27.290

Link: CVE-2022-24810

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-07-01T00:00:00Z

Links: CVE-2022-24810 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses