Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://salsa.debian.org/debian/net-snmp/-/commit/fad8725402752746daf0a751dcff19eb6aeab52e | third party advisory patch |
https://github.com/net-snmp/net-snmp/commit/77f6c60f57dba0aaea5d8ef1dd94bcd0c8e6d205 | third party advisory patch |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=965166 | issue tracking third party advisory |
https://security-tracker.debian.org/tracker/CVE-2020-15862 | third party advisory |
https://security.gentoo.org/glsa/202008-12 | third party advisory vendor advisory |
https://usn.ubuntu.com/4471-1/ | third party advisory vendor advisory |
https://security.netapp.com/advisory/ntap-20200904-0001/ | third party advisory |