snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HNetapp Cloud Backup
APPNetappall versionsNetapp Data Ontap
OSNetappall versionsNetapp E Series Santricity Os Controller
OSNetapp11.0 – 11.5Netapp Hyper Converged Infrastructure
APPNetappall versionsNetapp Solidfire Element Os
OSNetappall versionsNetapp Storagegrid Webscale
APPNetappall versionsNet Snmp
APPNet-Snmp< 5.8
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth BypassDoS
References
Related vulnerabilities
CVE-2021-42013CRITICAL9.8⚠ KEVPL ✓same product
Apache HTTP Server 2.4.50 — path traversal i RCE (niewystarczający patch CVE-2021-41773)
CVE-2021-41773CRITICAL9.8⚠ KEVPL ✓same product
Apache HTTP Server 2.4.49 — path traversal i RCE (aktywnie exploitowany)
CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same product
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
CVE-2025-68615CRITICAL9.8PL ✓same product
Buffer overflow w demonie snmptrapd biblioteki net-snmp
CVE-2023-28531CRITICAL9.8PL ✓same product
OpenSSH ssh-add: brak ograniczeń destination constraints dla kluczy smartcard