CVE-2020-15862
published 2020-08-20CVE-2020-15862: Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.38%
30.7th percentile
Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | net-snmp | < net-snmp 5.8+dfsg-4 (bookworm) | net-snmp 5.8+dfsg-4 (bookworm) |
| net-snmp | net-snmp | < 5.8.1 | 5.8.1 |
| net-snmp | net-snmp | >= 0 < 5.8+dfsg-4 | 5.8+dfsg-4 |
| net-snmp | net-snmp | >= 0 < 5.8+dfsg-4 | 5.8+dfsg-4 |
| net-snmp | net-snmp | >= 0 < 5.8+dfsg-4 | 5.8+dfsg-4 |
| net-snmp | net-snmp | >= 0 < 5.8+dfsg-4 | 5.8+dfsg-4 |
| net-snmp | net-snmp | >= 0 < 5.7.3+dfsg-1ubuntu4.5 | 5.7.3+dfsg-1ubuntu4.5 |
| net-snmp | net-snmp | >= 0 < 5.7.3+dfsg-1ubuntu4.6 | 5.7.3+dfsg-1ubuntu4.6 |
| net-snmp | net-snmp | >= 0 < 5.7.3+dfsg-1.8ubuntu3.5 | 5.7.3+dfsg-1.8ubuntu3.5 |
| net-snmp | net-snmp | >= 0 < 5.7.3+dfsg-1.8ubuntu3.6 | 5.7.3+dfsg-1.8ubuntu3.6 |
| net-snmp | net-snmp | >= 0 < 5.8+dfsg-2ubuntu2.3 | 5.8+dfsg-2ubuntu2.3 |
| net-snmp | net-snmp | >= 0 < 5.7.2~dfsg-8.1ubuntu3.3+esm1 | 5.7.2~dfsg-8.1ubuntu3.3+esm1 |
| net-snmp | net-snmp | >= 0 < 5.7.2~dfsg-8.1ubuntu3.3+esm2 | 5.7.2~dfsg-8.1ubuntu3.3+esm2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Net-SNMP regression
vendor_ubuntu·2020-09-01·CVSS 7.8
CVE-2020-15861 [HIGH] Net-SNMP regression
Title: Net-SNMP regression
Summary: USN-4471-1 introduced a regression in Net-SNMP.
USN-4471-1 fixed a vulnerability in Net-SNMP. The updated introduced a regression making
nsExtendCacheTime not settable. This update fixes the problem adding the cacheTime feature flag.
Original advisory details:
Tobias Neitzel discovered that Net-SNMP incorrectly handled certain symlinks.
An attacker could possibly use this issue to access sensitive information.
(CVE-2020-15861)
It was discovered that Net-SNMP incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04 LTS, Ubuntu
18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2020-15862)
Instructions: After a standard system update you need to restart snmpd t
Red Hat
net-snmp: Improper Privilege Management in EXTEND MIB may lead to privileged commands execution
vendor_redhat·2020-08-25·CVSS 7.8
CVE-2020-15862 [HIGH] CWE-250 net-snmp: Improper Privilege Management in EXTEND MIB may lead to privileged commands execution
net-snmp: Improper Privilege Management in EXTEND MIB may lead to privileged commands execution
Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.
A flaw was found in Net-SNMP through version 5.73, where an Improper Privilege Management issue occurs due to SNMP WRITE access to the EXTEND MIB allows running arbitrary commands as root. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Package: net-snmp (Red Hat Enterprise Linux 5) - Out of support scope
Ubuntu
Net-SNMP vulnerabilities
vendor_ubuntu·2020-08-24·CVSS 7.8
CVE-2020-15861 [HIGH] Net-SNMP vulnerabilities
Title: Net-SNMP vulnerabilities
Summary: Several security issues were fixed in Net-SNMP.
Tobias Neitzel discovered that Net-SNMP incorrectly handled certain symlinks.
An attacker could possibly use this issue to access sensitive information.
(CVE-2020-15861)
It was discovered that Net-SNMP incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04 LTS, Ubuntu
18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2020-15862)
Instructions: After a standard system update you need to restart snmpd to make
all the necessary changes.
Debian
CVE-2020-15862: net-snmp - Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access...
vendor_debian·2020·CVSS 7.8
CVE-2020-15862 [HIGH] CVE-2020-15862: net-snmp - Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access...
Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.
Scope: local
bookworm: resolved (fixed in 5.8+dfsg-4)
bullseye: resolved (fixed in 5.8+dfsg-4)
forky: resolved (fixed in 5.8+dfsg-4)
sid: resolved (fixed in 5.8+dfsg-4)
trixie: resolved (fixed in 5.8+dfsg-4)
GHSA
GHSA-wfc4-c3m6-rrjc: Net-SNMP through 5
ghsa_unreviewed·2022-05-24
CVE-2020-15862 [HIGH] CWE-269 GHSA-wfc4-c3m6-rrjc: Net-SNMP through 5
Net-SNMP through 5.7.3 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.
OSV
net-snmp regression
osv·2020-09-01·CVSS 7.8
CVE-2020-15861 [HIGH] net-snmp regression
net-snmp regression
USN-4471-1 fixed a vulnerability in Net-SNMP. The updated introduced a regression making
nsExtendCacheTime not settable. This update fixes the problem adding the cacheTime feature flag.
Original advisory details:
Tobias Neitzel discovered that Net-SNMP incorrectly handled certain symlinks.
An attacker could possibly use this issue to access sensitive information.
(CVE-2020-15861)
It was discovered that Net-SNMP incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04 LTS, Ubuntu
18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2020-15862)
OSV
net-snmp vulnerabilities
osv·2020-08-24·CVSS 7.8
CVE-2020-15861 [HIGH] net-snmp vulnerabilities
net-snmp vulnerabilities
Tobias Neitzel discovered that Net-SNMP incorrectly handled certain symlinks.
An attacker could possibly use this issue to access sensitive information.
(CVE-2020-15861)
It was discovered that Net-SNMP incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04 LTS, Ubuntu
18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2020-15862)
OSV
CVE-2020-15862: Net-SNMP through 5
osv·2020-08-20·CVSS 7.8
CVE-2020-15862 [HIGH] CVE-2020-15862: Net-SNMP through 5
Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.
No detection rules found.
No public exploits indexed.
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=965166https://github.com/net-snmp/net-snmp/commit/77f6c60f57dba0aaea5d8ef1dd94bcd0c8e6d205https://salsa.debian.org/debian/net-snmp/-/commit/fad8725402752746daf0a751dcff19eb6aeab52ehttps://security-tracker.debian.org/tracker/CVE-2020-15862https://security.gentoo.org/glsa/202008-12https://security.netapp.com/advisory/ntap-20200904-0001/https://usn.ubuntu.com/4471-1/https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=965166https://github.com/net-snmp/net-snmp/commit/77f6c60f57dba0aaea5d8ef1dd94bcd0c8e6d205https://salsa.debian.org/debian/net-snmp/-/commit/fad8725402752746daf0a751dcff19eb6aeab52ehttps://security-tracker.debian.org/tracker/CVE-2020-15862https://security.gentoo.org/glsa/202008-12https://security.netapp.com/advisory/ntap-20200904-0001/https://usn.ubuntu.com/4471-1/
2020-08-20
Published