CVE-2015-5677

MEDIUM

bsnmpd - Info Disclosure

Title source: llm

Description

bsnmpd, as used in FreeBSD 9.3, 10.1, and 10.2, uses world-readable permissions on the snmpd.config file, which allows local users to obtain the secret key for USM authentication by reading the file.

Scores

CVSS v3 5.5
EPSS 0.0009
EPSS Percentile 25.0%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-200
Status published

Affected Products (4)

freebsd/freebsd
freebsd/freebsd
freebsd/freebsd
n/a/n/a

Timeline

Published Feb 07, 2017
Tracked Since Feb 18, 2026