← Vulnerability feed

Vulnerability record · CVE-2015-5621 · published 19 August 2015

CVE-2015-5621: Net-snmp integer overflow vulnerability

Net Snmp · Net Snmp

The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.

7.5 CVSS 3.1 High EPSS 41% · top 1.4% CWE-19 · CWE-19CWE-190 · Integer overflow
7.5CVSS 3.1 base score, v2 7.5
41%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
30References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-updates/2015-09/msg00004.html
http://rhn.redhat.com/errata/RHSA-2015-1636.html
http://sourceforge.net/p/net-snmp/code/ci/f23bcd3ac6ddee5d0a48f9703007ccc738914791/
http://support.citrix.com/article/CTX209443
http://www.openwall.com/lists/oss-security/2015/04/13/1 Exploit
http://www.openwall.com/lists/oss-security/2015/04/16/15
http://www.openwall.com/lists/oss-security/2015/07/31/1
http://www.securityfocus.com/bid/76380
http://www.securitytracker.com/id/1033304
http://www.ubuntu.com/usn/USN-2711-1
https://bugzilla.redhat.com/show_bug.cgi?id=1212408
https://cert-portal.siemens.com/productcert/pdf/ssa-978220.pdf
https://sourceforge.net/p/net-snmp/bugs/2615/
https://www.debian.org/security/2018/dsa-4154
https://www.exploit-db.com/exploits/45547/
http://lists.opensuse.org/opensuse-updates/2015-09/msg00004.html
http://rhn.redhat.com/errata/RHSA-2015-1636.html
http://sourceforge.net/p/net-snmp/code/ci/f23bcd3ac6ddee5d0a48f9703007ccc738914791/
http://support.citrix.com/article/CTX209443
http://www.openwall.com/lists/oss-security/2015/04/13/1 Exploit
http://www.openwall.com/lists/oss-security/2015/04/16/15
http://www.openwall.com/lists/oss-security/2015/07/31/1
http://www.securityfocus.com/bid/76380
http://www.securitytracker.com/id/1033304
http://www.ubuntu.com/usn/USN-2711-1
https://bugzilla.redhat.com/show_bug.cgi?id=1212408
https://cert-portal.siemens.com/productcert/pdf/ssa-978220.pdf
https://sourceforge.net/p/net-snmp/bugs/2615/
https://www.debian.org/security/2018/dsa-4154
https://www.exploit-db.com/exploits/45547/

Track CVE-2015-5621 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-4837Net-snmp vulnerabilitysnmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allows remote …EPSS 9.7%10.0CVE-2005-1740Net-snmp vulnerabilityfixproc in Net-snmp 5.x before 5.2.1-r1 creates temporary files insecurely, which allows local users to modify the contents of those files to execute…EPSS 8.6%9.8CVE-2025-68615Net-snmp memory buffer overflow vulnerabilitynet-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd …EPSS 42%9.8CVE-2018-1000116Net-snmp out-of-bounds write vulnerabilityNET-SNMP version 5.7.2 contains a heap corruption vulnerability in the UDP protocol handler that can result in command execution.EPSS 6.3%8.8CVE-2022-24810Net-snmp null pointer dereference vulnerabilitynet-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can us…EPSS 1.1%8.8CVE-2022-24805Net-snmp classic buffer overflow vulnerabilitynet-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a buffer overflow in the handling of the …EPSS 1.3%7.8CVE-2020-15861Net-snmp link following vulnerabilityNet-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following.EPSS 0.46%7.8CVE-2020-15862Net-snmp improper privilege management vulnerabilityNet-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as …EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2015-5621), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.