CVE Vulnerabilities

CVE-2020-15862

Improper Privilege Management

Published: Aug 20, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
8.8 IMPORTANT
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Net-snmpNet-snmp*5.8.1 (excluding)
Red Hat Enterprise Linux 6RedHatnet-snmp-1:5.5-60.el6_10.2*
Red Hat Enterprise Linux 7RedHatnet-snmp-1:5.7.2-49.el7_9.1*
Red Hat Enterprise Linux 7.4 Advanced Update SupportRedHatnet-snmp-1:5.7.2-28.el7_4.4*
Red Hat Enterprise Linux 7.4 Telco Extended Update SupportRedHatnet-snmp-1:5.7.2-28.el7_4.4*
Red Hat Enterprise Linux 7.4 Update Services for SAP SolutionsRedHatnet-snmp-1:5.7.2-28.el7_4.4*
Red Hat Enterprise Linux 7.6 Extended Update SupportRedHatnet-snmp-1:5.7.2-38.el7_6.3*
Red Hat Enterprise Linux 7.7 Extended Update SupportRedHatnet-snmp-1:5.7.2-43.el7_7.7*
Red Hat Enterprise Linux 8RedHatnet-snmp-1:5.8-18.el8_3.1*
Red Hat Enterprise Linux 8RedHatnet-snmp-1:5.8-18.el8_3.1*
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionsRedHatnet-snmp-1:5.8-7.el8_0.4*
Red Hat Enterprise Linux 8.1 Extended Update SupportRedHatnet-snmp-1:5.8-12.el8_1.3*
Red Hat Enterprise Linux 8.2 Extended Update SupportRedHatnet-snmp-1:5.8-14.el8_2.3*
Net-snmpUbuntubionic*
Net-snmpUbuntudevel*
Net-snmpUbuntuesm-infra-legacy/trusty*
Net-snmpUbuntuesm-infra/bionic*
Net-snmpUbuntuesm-infra/focal*
Net-snmpUbuntuesm-infra/xenial*
Net-snmpUbuntufocal*
Net-snmpUbuntutrusty*
Net-snmpUbuntutrusty/esm*
Net-snmpUbuntuupstream*
Net-snmpUbuntuxenial*

Potential Mitigations

References