The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not properly parse hosts.allow rules, which allows remote attackers to bypass intended access restrictions and execute SNMP queries, related to "source/destination IP address confusion."
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade net-snmp | Jul 30, 2024 | Feb 12, 2009 |
| Gentoo Linux | — | Upgrade net-analyzer/net-snmp. | Oct 30, 2017 | Feb 12, 2009 |
| Suse | — | Upgrade libsnmp15-openssl1Upgrade snmp-mibsUpgrade net-snmpUpgrade net-snmp-devel-32bitUpgrade libsnmp15Upgrade libsnmp15-openssl1-32bitUpgrade libsnmp15-32bitUpgrade perl-SNMPUpgrade libsnmp15-x86Upgrade net-snmp-devel | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libsnmp15 | Nov 8, 2024 | Feb 12, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub