HIGH · 7.5

CVE-2018-18066

snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP...

Vulnerability Description

snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
Net-SnmpNet-Snmp< 5.8
NetappCloud Backup-
NetappHyper Converged Infrastructure-
NetappStoragegrid Webscale-
NetappData Ontap-
NetappE-Series Santricity Os Controller>= 11.0, <= 11.5
NetappSolidfire Element Os-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-18066?

CVE-2018-18066 is a vulnerability with a CVSS score of 7.5 (HIGH). snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP...

How severe is CVE-2018-18066?

CVE-2018-18066 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-18066?

Check the references section above for vendor advisories and patch information. Affected products include: Net-Snmp Net-Snmp, Netapp Cloud Backup, Netapp Hyper Converged Infrastructure, Netapp Storagegrid Webscale, Netapp Data Ontap.