cbcvebase.
CVE-2008-6123
published 2009-02-12

CVE-2008-6123: The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not…

PriorityP430medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.92%
85.5th percentile
The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not properly parse hosts.allow rules, which allows remote attackers to bypass intended access restrictions and execute SNMP queries, related to "source/destination IP address confusion."

Affected

10 ranges
VendorProductVersion rangeFixed in
debiannet-snmp< net-snmp 5.4.3~dfsg-1 (bookworm)net-snmp 5.4.3~dfsg-1 (bookworm)
net-snmpnet-snmp>= 0 < 5.4.3~dfsg-15.4.3~dfsg-1
net-snmpnet-snmp>= 0 < 5.4.3~dfsg-15.4.3~dfsg-1
net-snmpnet-snmp>= 0 < 5.4.3~dfsg-15.4.3~dfsg-1
net-snmpnet-snmp>= 0 < 5.4.3~dfsg-15.4.3~dfsg-1
net-snmpnet-snmp5.0.9 – 5.4.2.1
opensuseopensuse
opensuseopensuse
redhatenterprise_linux
suselinux_enterprise

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.