CVE-2015-5621
HIGHnet-snmp < 5.7.2 - Denial of Service and Possible Remote Code Execution via Crafted SNMP PDU
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-5621. PoCs published by Magnus Klaaborg Stubman.
AI-analyzed exploit summary This exploit demonstrates a remote Denial of Service (DoS) vulnerability in NET-SNMP (CVE-2018-18065) by sending a malformed base64-decoded payload to a vulnerable snmpd instance, causing a segmentation fault. The PoC includes a base64-encoded payload and a command to trigger the crash.
Description
The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.
Exploits (1)
This exploit demonstrates a remote Denial of Service (DoS) vulnerability in NET-SNMP (CVE-2018-18065) by sending a malformed base64-decoded payload to a vulnerable snmpd instance, causing a segmentation fault. The PoC includes a base64-encoded payload and a command to trigger the crash.
References (15)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H