ISOMAN

CVE

CVE-2020-15862

Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.

Severity
HIGH
CVSS
7.8
Published
Modified

Linked Releases

DistributionReleaseStatusEvidence
Ubuntu20.04.6 amd64 desktopunknownsource
Ubuntu20.04.6 amd64 live-serverunknownsource

References

  1. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=965166
  2. https://github.com/net-snmp/net-snmp/commit/77f6c60f57dba0aaea5d8ef1dd94bcd0c8e6d205
  3. https://salsa.debian.org/debian/net-snmp/-/commit/fad8725402752746daf0a751dcff19eb6aeab52e
  4. https://security-tracker.debian.org/tracker/CVE-2020-15862
  5. https://security.gentoo.org/glsa/202008-12
  6. https://security.netapp.com/advisory/ntap-20200904-0001/
  7. https://usn.ubuntu.com/4471-1/
  8. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=965166
  9. https://github.com/net-snmp/net-snmp/commit/77f6c60f57dba0aaea5d8ef1dd94bcd0c8e6d205
  10. https://salsa.debian.org/debian/net-snmp/-/commit/fad8725402752746daf0a751dcff19eb6aeab52e
  11. https://security-tracker.debian.org/tracker/CVE-2020-15862
  12. https://security.gentoo.org/glsa/202008-12
  13. https://security.netapp.com/advisory/ntap-20200904-0001/
  14. https://usn.ubuntu.com/4471-1/