CVE-2020-4471
published 2020-06-15CVE-2020-4471: IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow an unauthenticated attacker to cause a denial of service or hijack DNS sessions by send a specially…
PriorityP433medium6.5CVSS 3.1
AVNACLPRNUINSUCNILAL
EPSS
2.65%
83.9th percentile
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow an unauthenticated attacker to cause a denial of service or hijack DNS sessions by send a specially crafted HTTP command to the remote server. IBM X-Force ID: 181726.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | spectrum_protect_plus | — | — |
| ibm | spectrum_protect_plus | — | — |
| ibm | spectrum_protect_plus | 10.1.0 – 10.1.5 | — |
| net-snmp | net-snmp | >= 0 < 5.7.3+dfsg-1ubuntu4.6 | 5.7.3+dfsg-1ubuntu4.6 |
| net-snmp | net-snmp | >= 0 < 5.7.3+dfsg-1.8ubuntu3.6 | 5.7.3+dfsg-1.8ubuntu3.6 |
| net-snmp | net-snmp | >= 0 < 5.7.2~dfsg-8.1ubuntu3.3+esm2 | 5.7.2~dfsg-8.1ubuntu3.3+esm2 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
nvdv3.04.8MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m6hc-4f95-rgqf: IBM Spectrum Protect Plus 10
ghsa_unreviewed·2022-05-24
CVE-2020-4471 [MEDIUM] CWE-20 GHSA-m6hc-4f95-rgqf: IBM Spectrum Protect Plus 10
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow an unauthenticated attacker to cause a denial of service or hijack DNS sessions by send a specially crafted HTTP command to the remote server. IBM X-Force ID: 181726.
OSV
net-snmp regression
osv·2020-09-01·CVSS 7.8
CVE-2020-15861 net-snmp regression
net-snmp regression
USN-4471-1 fixed a vulnerability in Net-SNMP. The updated introduced a regression making
nsExtendCacheTime not settable. This update fixes the problem adding the cacheTime feature flag.
Original advisory details:
Tobias Neitzel discovered that Net-SNMP incorrectly handled certain symlinks.
An attacker could possibly use this issue to access sensitive information.
(CVE-2020-15861)
It was discovered that Net-SNMP incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04 LTS, Ubuntu
18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2020-15862)
No detection rules found.
No public exploits indexed.
https://exchange.xforce.ibmcloud.com/vulnerabilities/181726https://www.ibm.com/support/pages/node/6221358https://www.tenable.com/security/research/tra-2020-37https://exchange.xforce.ibmcloud.com/vulnerabilities/181726https://www.ibm.com/support/pages/node/6221358https://www.tenable.com/security/research/tra-2020-37
2020-06-15
Published