CVE-2018-18065
MEDIUMNet-SNMP < 5.8 - Authenticated Denial of Service via Crafted UDP Packet
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-18065. PoCs published by Magnus Klaaborg Stubman.
AI-analyzed exploit summary This exploit demonstrates a remote Denial of Service (DoS) vulnerability in NET-SNMP (CVE-2018-18065) by sending a malformed base64-decoded payload to a vulnerable snmpd instance, causing a segmentation fault. The PoC includes a base64-encoded payload and a command to trigger the crash.
Description
_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
Exploits (1)
This exploit demonstrates a remote Denial of Service (DoS) vulnerability in NET-SNMP (CVE-2018-18065) by sending a malformed base64-decoded payload to a vulnerable snmpd instance, causing a segmentation fault. The PoC includes a base64-encoded payload and a command to trigger the crash.
References (12)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H