CVE-2014-2310
published 2014-04-17CVE-2014-2310: The AgentX subagent in Net-SNMP before 5.4.4 allows remote attackers to cause a denial of service (hang) by sending a multi-object request with an Object ID…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.99%
78.4th percentile
The AgentX subagent in Net-SNMP before 5.4.4 allows remote attackers to cause a denial of service (hang) by sending a multi-object request with an Object ID (OID) containing more subids than previous requests, a different vulnerability than CVE-2012-6151.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | net-snmp | < net-snmp 5.7.2~dfsg-3 (bookworm) | net-snmp 5.7.2~dfsg-3 (bookworm) |
| net-snmp | net-snmp | <= 5.4 | — |
| net-snmp | net-snmp | >= 0 < 5.7.2~dfsg-3 | 5.7.2~dfsg-3 |
| net-snmp | net-snmp | >= 0 < 5.7.2~dfsg-3 | 5.7.2~dfsg-3 |
| net-snmp | net-snmp | >= 0 < 5.7.2~dfsg-3 | 5.7.2~dfsg-3 |
| net-snmp | net-snmp | >= 0 < 5.7.2~dfsg-3 | 5.7.2~dfsg-3 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Net-SNMP vulnerabilities
vendor_ubuntu·2014-04-14·CVSS 4.3
CVE-2012-6151 [MEDIUM] Net-SNMP vulnerabilities
Title: Net-SNMP vulnerabilities
Summary: Net-SNMP could be made to crash if it received specially crafted network
traffic.
Ken Farnen discovered that Net-SNMP incorrectly handled AgentX timeouts. A
remote attacker could use this issue to cause the server to crash or to
hang, resulting in a denial of service. (CVE-2012-6151)
It was discovered that the Net-SNMP ICMP-MIB incorrectly validated input. A
remote attacker could use this issue to cause the server to crash,
resulting in a denial of service. This issue only affected Ubuntu 13.10.
(CVE-2014-2284)
Viliam Púčik discovered that the Net-SNMP perl trap handler incorrectly
handled NULL arguments. A remote attacker could use this issue to cause the
server to crash, resulting in a denial of service. (CVE-2014-2285)
It was discovered that
Red Hat
net-snmp: AgentX incorrectly handles multi-object requests leading to DoS
vendor_redhat·2014-03-06·CVSS 4.3
CVE-2014-2310 [MEDIUM] net-snmp: AgentX incorrectly handles multi-object requests leading to DoS
net-snmp: AgentX incorrectly handles multi-object requests leading to DoS
The AgentX subagent in Net-SNMP before 5.4.4 allows remote attackers to cause a denial of service (hang) by sending a multi-object request with an Object ID (OID) containing more subids than previous requests, a different vulnerability than CVE-2012-6151.
Package: net-snmp (Red Hat Enterprise Linux 5) - Not affected
Package: net-snmp (Red Hat Enterprise Linux 6) - Not affected
Package: net-snmp (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2014-2310: net-snmp - The AgentX subagent in Net-SNMP before 5.4.4 allows remote attackers to cause a ...
vendor_debian·2014·CVSS 4.3
CVE-2014-2310 [MEDIUM] CVE-2014-2310: net-snmp - The AgentX subagent in Net-SNMP before 5.4.4 allows remote attackers to cause a ...
The AgentX subagent in Net-SNMP before 5.4.4 allows remote attackers to cause a denial of service (hang) by sending a multi-object request with an Object ID (OID) containing more subids than previous requests, a different vulnerability than CVE-2012-6151.
Scope: local
bookworm: resolved (fixed in 5.7.2~dfsg-3)
bullseye: resolved (fixed in 5.7.2~dfsg-3)
forky: resolved (fixed in 5.7.2~dfsg-3)
sid: resolved (fixed in 5.7.2~dfsg-3)
trixie: resolved (fixed in 5.7.2~dfsg-3)
GHSA
GHSA-7x87-wr85-45rj: The AgentX subagent in Net-SNMP before 5
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2014-2310 [MEDIUM] CWE-20 GHSA-7x87-wr85-45rj: The AgentX subagent in Net-SNMP before 5
The AgentX subagent in Net-SNMP before 5.4.4 allows remote attackers to cause a denial of service (hang) by sending a multi-object request with an Object ID (OID) containing more subids than previous requests, a different vulnerability than CVE-2012-6151.
OSV
CVE-2014-2310: The AgentX subagent in Net-SNMP before 5
osv·2014-04-17·CVSS 4.3
CVE-2014-2310 [MEDIUM] CVE-2014-2310: The AgentX subagent in Net-SNMP before 5
The AgentX subagent in Net-SNMP before 5.4.4 allows remote attackers to cause a denial of service (hang) by sending a multi-object request with an Object ID (OID) containing more subids than previous requests, a different vulnerability than CVE-2012-6151.
No detection rules found.
No public exploits indexed.
http://seclists.org/oss-sec/2014/q1/513http://seclists.org/oss-sec/2014/q1/527http://secunia.com/advisories/57870http://sourceforge.net/p/net-snmp/code/ci/eb816330a1887798d844d2fd5dc6482002123cbd/http://sourceforge.net/p/net-snmp/patches/1113/http://ubuntu.com/usn/usn-2166-1https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=684388http://seclists.org/oss-sec/2014/q1/513http://seclists.org/oss-sec/2014/q1/527http://secunia.com/advisories/57870http://sourceforge.net/p/net-snmp/code/ci/eb816330a1887798d844d2fd5dc6482002123cbd/http://sourceforge.net/p/net-snmp/patches/1113/http://ubuntu.com/usn/usn-2166-1https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=684388
2014-04-17
Published