CVE-2002-0013
Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via (1) GetRequest, (2) GetNextRequest, and (3) SetRequest messages, as demonstrated by the…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 51.1%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via (1) GetRequest, (2) GetNextRequest, and (3) SetRequest messages, as demonstrated by the PROTOS c06-SNMPv1 test suite. NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor. This and other SNMP-related candidates will be updated when more accurate information is available.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 51.13% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- snmp/snmp
- Source
- cve@mitre.org
References
- ftp://patches.sgi.com/support/free/security/advisories/20020201-01-APatch, Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-57404-1Patch, Vendor Advisory
- http://www.cert.org/advisories/CA-2002-03.htmlThird Party Advisory, US Government Resource
- http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/snmpv1/index.html
- http://www.iss.net/security_center/alerts/advise110.phpVendor Advisory
- http://www.kb.cert.org/vuls/id/854306Third Party Advisory, US Government Resource
- http://www.redhat.com/support/errata/RHSA-2001-163.htmlVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-006
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A298
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A87
- ftp://patches.sgi.com/support/free/security/advisories/20020201-01-APatch, Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-57404-1Patch, Vendor Advisory
- http://www.cert.org/advisories/CA-2002-03.htmlThird Party Advisory, US Government Resource
- http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/snmpv1/index.html
- http://www.iss.net/security_center/alerts/advise110.phpVendor Advisory
- http://www.kb.cert.org/vuls/id/854306Third Party Advisory, US Government Resource
- http://www.redhat.com/support/errata/RHSA-2001-163.htmlVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-006
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A298
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A87
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.