SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-6123

The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not properly parse hosts.allow rules, which allows remote attackers to bypass intended access…

MEDIUM 5.0EPSS 2.92%

Does this matter?

Lower severity and a low EPSS score (2.92%). Track it; it rarely justifies an emergency change on its own.

Description

The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not properly parse hosts.allow rules, which allows remote attackers to bypass intended access restrictions and execute SNMP queries, related to "source/destination IP address confusion."

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
2.92% probability · 86th percentile
CISA KEV
Not listed
Weakness
CWE-863
Affected
net-snmp/net-snmp · opensuse/opensuse · suse/linux enterprise · redhat/enterprise linux
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.