CVE-2020-15862

HIGH

Net-SNMP < 5.8.1 - Authenticated Remote Code Execution via EXTEND MIB

Title source: llm
STIX 2.1

Description

Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.

Scores

CVSS v3 7.8
EPSS 0.0038
EPSS Percentile 29.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-269
Status published
Products (10)
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 20.04
net-snmp/net-snmp < 5.8.1
netapp/cloud_backup
netapp/hci_management_node
netapp/smi-s_provider
netapp/solidfire
Published Aug 20, 2020
Tracked Since Feb 18, 2026