Vulnerability record · CVE-2022-24806 · published 16 April 2024
CVE-2022-24806: Net-snmp improper input validation vulnerability
Net Snmp · Net Snmp
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can exploit an Improper Input Validation vulnerability when SETing malformed OIDs in master agent and subagent simultaneously. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and avoid sharing the credentials. Those who must use SNMPv1 or SNMPv2c should use a complex community string and enhance the protection by restricting access to a given IP address range.
Description
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can exploit an Improper Input Validation vulnerability when SETing malformed OIDs in master agent and subagent simultaneously. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and avoid sharing the credentials. Those who must use SNMPv1 or SNMPv2c should use a complex community string and enhance the protection by restricting access to a given IP address range.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected products
15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=2103225 | Third Party Advisory |
| https://github.com/net-snmp/net-snmp/commit/ce66eb97c17aa9a48bc079be7b65895266fa6775 | Patch |
| https://lists.debian.org/debian-lts-announce/2022/08/msg00020.html | Third Party Advisory |
| https://lists.fedoraproject.org/archives/list/[email protected]/message/FX75KKGMO5XMV6JMQZF6KOG3J | Product |
| https://security.gentoo.org/glsa/202210-29 | Third Party Advisory |
| https://www.debian.org/security/2022/dsa-5209 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2103225 | Third Party Advisory |
| https://github.com/net-snmp/net-snmp/commit/ce66eb97c17aa9a48bc079be7b65895266fa6775 | Patch |
| https://lists.debian.org/debian-lts-announce/2022/08/msg00020.html | Third Party Advisory |
| https://lists.fedoraproject.org/archives/list/[email protected]/message/FX75KKGMO5XMV6JMQZF6KOG3J | Product |
| https://security.gentoo.org/glsa/202210-29 | Third Party Advisory |
| https://www.debian.org/security/2022/dsa-5209 | Third Party Advisory |
Track CVE-2022-24806 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-24806), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.