
Cloud Vulnerability DB
A community-led vulnerabilities database
Net-SNMP, prior to version 5.9.2, contained an Improper Input Validation vulnerability (CVE-2022-24806) that affects users with read-write credentials. The vulnerability occurs when SETing malformed OIDs in master agent and subagent simultaneously (CVE-MITRE, Debian-Security).
The vulnerability is related to improper input validation when handling SET operations with malformed Object Identifiers (OIDs) in both master agent and subagent simultaneously. The vulnerability has been assigned a CVSS v3.1 base score of 5.3 (Medium), with the following metrics: Attack Vector: Network, Attack Complexity: High, Privileges Required: Low, User Interaction: None, Scope: Unchanged, Confidentiality: None, Integrity: None, Availability: High (Ubuntu-Security).
The exploitation of this vulnerability could lead to denial of service conditions in the affected systems. The vulnerability specifically affects the availability of the system while maintaining no impact on confidentiality or integrity (Ubuntu-Security).
The vulnerability requires read-write credentials for exploitation. The attack complexity is considered high, and the attack vector is network-based. An attacker would need low-level privileges to execute the exploit (Ubuntu-Security).
The vulnerability has been patched in Net-SNMP version 5.9.2. Users are recommended to upgrade to this version or later. For those unable to upgrade immediately, it is recommended to use strong SNMPv3 credentials and avoid sharing them. If using SNMPv1 or SNMPv2c, users should implement a complex community string and enhance protection by restricting access to specific IP address ranges (Debian-Security, Net-SNMP-Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."