Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-15862

Опубликовано: 25 авг. 2020
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.

A flaw was found in Net-SNMP through version 5.73, where an Improper Privilege Management issue occurs due to SNMP WRITE access to the EXTEND MIB allows running arbitrary commands as root. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5net-snmpOut of support scope
Red Hat Enterprise Linux 6net-snmpFixedRHSA-2020:512917.11.2020
Red Hat Enterprise Linux 7net-snmpFixedRHSA-2020:535007.12.2020
Red Hat Enterprise Linux 7.4 Advanced Update Supportnet-snmpFixedRHSA-2021:025726.01.2021
Red Hat Enterprise Linux 7.4 Telco Extended Update Supportnet-snmpFixedRHSA-2021:025726.01.2021
Red Hat Enterprise Linux 7.4 Update Services for SAP Solutionsnet-snmpFixedRHSA-2021:025726.01.2021
Red Hat Enterprise Linux 7.6 Extended Update Supportnet-snmpFixedRHSA-2021:035802.02.2021
Red Hat Enterprise Linux 7.7 Extended Update Supportnet-snmpFixedRHSA-2021:052516.02.2021
Red Hat Enterprise Linux 8net-snmpFixedRHSA-2020:548015.12.2020
Red Hat Enterprise Linux 8net-snmpFixedRHSA-2020:548015.12.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-250
https://bugzilla.redhat.com/show_bug.cgi?id=1873038net-snmp: Improper Privilege Management in EXTEND MIB may lead to privileged commands execution

EPSS

Процентиль: 20%
0.00063
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 5 лет назад

Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.

CVSS3: 7.8
nvd
больше 5 лет назад

Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.

CVSS3: 7.8
debian
больше 5 лет назад

Net-SNMP through 5.8 has Improper Privilege Management because SNMP WR ...

suse-cvrf
около 4 лет назад

Security update for net-snmp

suse-cvrf
около 4 лет назад

Security update for net-snmp

EPSS

Процентиль: 20%
0.00063
Низкий

8.8 High

CVSS3