cbcvebase.
CVE-2025-68615
published 2025-12-23

CVE-2025-68615: net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can…

PriorityP273critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
43.26%
98.6th percentile
net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd daemon can cause a buffer overflow and the daemon to crash. This issue has been patched in versions 5.9.5 and 5.10.pre2.

Affected

11 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiannet-snmp< net-snmp 5.9.3+dfsg-2+deb12u1 (bookworm)net-snmp 5.9.3+dfsg-2+deb12u1 (bookworm)
msrcazl3_net-snmp_5.9.4-1_on_azure_linux_3.0
msrccbl2_net-snmp_5.9.4-1_on_cbl_mariner_2.0
net-snmpnet-snmp< 5.9.55.9.5
net-snmpnet-snmp
net-snmpnet-snmp
net-snmpnet-snmp>= 0 < 5.9+dfsg-4+deb11u35.9+dfsg-4+deb11u3
net-snmpnet-snmp>= 0 < 5.9.3+dfsg-2+deb12u15.9.3+dfsg-2+deb12u1
net-snmpnet-snmp>= 0 < 5.9.4+dfsg-2+deb13u15.9.4+dfsg-2+deb13u1
net-snmpnet-snmp>= 0 < 5.9.5.2+dfsg-15.9.5.2+dfsg-1

Detection & IOCsextracted from sources · hover to see the quote

  • Target process: snmptrapd daemon is the vulnerable component; monitor for unexpected crashes or restarts of snmptrapd as a potential indicator of exploitation attempts
  • Attack vector: unauthenticated remote attacker sends a specially crafted SNMP packet to trigger the buffer overflow in snmptrapd; monitor SNMP trap ports (UDP/162) for anomalous or malformed packets from untrusted sources
  • Scope: SNMP ports exposed to public networks significantly increase exploitation risk; audit firewall rules to ensure SNMP ports are not reachable from untrusted networks
  • Mitigation/detection boundary: restrict network traffic to snmptrapd using firewall rules; alert on SNMP trap traffic from unknown or untrusted source IPs
  • ·Default Red Hat Enterprise Linux mitigations (SELinux, ASLR, memory protections) reduce exploitability; detections tuned for RCE may have lower fidelity on hardened RHEL systems
  • ·Red Hat Enterprise Linux 6 will NOT be patched (marked 'Will not fix'); snmptrapd on RHEL 6 remains permanently vulnerable and should be treated as a high-risk asset
  • ·Red Hat OpenShift Container Platform 4 (rhcos) is listed as Affected; container environments running snmptrapd should be assessed separately
  • ·Although the primary impact is DoS (daemon crash), memory corruption and arbitrary code execution cannot be ruled out; detection logic should account for both crash-based and potential RCE exploitation paths

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.