CVE-2018-18066
net-snmp: NULL pointer exception in snmp_oid_compare in snmplib/snmp_api.c resulting in a denial of service
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
snmp_oid_compare en snmplib/snmp_api.c en Net-SNMP en versiones anteriores a la 5.8 tiene un error de excepción de puntero NULL que puede ser empleado por un atacante no autenticado para provocar el cierre inesperado de la instancia de forma remota mediante un paquete UDP manipulado, lo que resulta en una denegación de servicio (DoS).
The net-snmp packages provide various libraries and tools for the Simple Network Management Protocol, including an SNMP library, an extensible agent, tools for requesting or setting information from SNMP agents, tools for generating and handling SNMP traps, a version of the netstat command which uses SNMP, and a Tk/Perl Management Information Base browser. Issues addressed include denial of service, double free, memory leak, and null pointer vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-10-08 CVE Reserved
- 2018-10-08 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-476: NULL Pointer Dereference
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
https://security.netapp.com/advisory/ntap-20181107-0001 | Third Party Advisory |
|
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html | X_refsource_misc |
|
URL | Date | SRC |
---|---|---|
https://dumpco.re/blog/net-snmp-5.7.3-remote-dos | 2024-08-05 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2018-18066 | 2020-06-12 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1637572 | 2020-06-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Net-snmp Search vendor "Net-snmp" | Net-snmp Search vendor "Net-snmp" for product "Net-snmp" | < 5.8 Search vendor "Net-snmp" for product "Net-snmp" and version " < 5.8" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Cloud Backup Search vendor "Netapp" for product "Cloud Backup" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Hyper Converged Infrastructure Search vendor "Netapp" for product "Hyper Converged Infrastructure" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Storagegrid Webscale Search vendor "Netapp" for product "Storagegrid Webscale" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Data Ontap Search vendor "Netapp" for product "Data Ontap" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | E-series Santricity Os Controller Search vendor "Netapp" for product "E-series Santricity Os Controller" | >= 11.0 <= 11.5 Search vendor "Netapp" for product "E-series Santricity Os Controller" and version " >= 11.0 <= 11.5" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Solidfire Element Os Search vendor "Netapp" for product "Solidfire Element Os" | - | - |
Affected
|