Vulnerability record · CVE-2002-0013 · published 13 February 2002
CVE-2002-0013: SNMPv1 request handling flaws allow remote DoS and privilege gain
Snmp · Snmp
Multiple SNMPv1 implementations mishandle GetRequest, GetNextRequest, and SetRequest messages, as demonstrated by the PROTOS c06-SNMPv1 test suite. The record is a broad candidate covering many vendors and is expected to be split, so affected products and versions are not enumerated here. It matters because SNMP is widely deployed for network management and these flaws can be triggered remotely.
Description
Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via (1) GetRequest, (2) GetNextRequest, and (3) SetRequest messages, as demonstrated by the PROTOS c06-SNMPv1 test suite. NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor. This and other SNMP-related candidates will be updated when more accurate information is available.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityCVSS 10.0 with no authentication required and high EPSS, but the record is a broad candidate lacking specific affected products and confirmed in-the-wild exploitation.
What it is
Multiple SNMPv1 implementations mishandle GetRequest, GetNextRequest, and SetRequest messages, as demonstrated by the PROTOS c06-SNMPv1 test suite. The record is a broad candidate covering many vendors and is expected to be split, so affected products and versions are not enumerated here. It matters because SNMP is widely deployed for network management and these flaws can be triggered remotely.
Impact
A remote attacker can cause a denial of service or gain privileges on the affected SNMP implementation. The full scope of privilege gain is not detailed in this record.
Attack surface
Reached over the network via SNMPv1 request messages (GetRequest, GetNextRequest, SetRequest) sent to the SNMP service. The CVSS vector indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented. EPSS is high (0.51126, 98.9th percentile), and references are vendor advisories and patches rather than exploit code.
What to do
- Apply vendor patches or updates for the SNMP implementation in use, referencing the vendor advisories in the references.
- Disable SNMPv1 where possible and use SNMPv3 with authentication and encryption.
- Restrict SNMP access to trusted management hosts using ACLs, firewalls, and network segmentation.
- Change default SNMP community strings and avoid guessable values.
- Monitor vendor advisories for the split CVE records that will identify specific affected products.
Detection
- Monitor for malformed or unusual SNMPv1 GetRequest, GetNextRequest, and SetRequest traffic on UDP 161/162.
- Alert on SNMP service crashes, restarts, or unexpected process termination on managed devices.
- Baseline normal SNMP request patterns and flag deviations in volume or structure.
- Review SNMP access logs for requests from untrusted source addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2002-0013 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2002-0013), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.