CVE-2020-15862

Description

Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.063

Associated Vulnerability

VulnerabilityOS Platform
SNMP (Simple Network Management Protocol) server and applications (USN-4471-1) snmpd_5.8+dfsg-2ubuntu2.3_i386.debLinux
SNMP (Simple Network Management Protocol) server and applications (USN-4471-1) snmpd_5.8+dfsg-2ubuntu2.3_amd64.debLinux
SNMP (Simple Network Management Protocol) server and applications (USN-4471-1) snmpd_5.7.3+dfsg-1ubuntu4.5_i386.debLinux
SNMP (Simple Network Management Protocol) server and applications (USN-4471-1) snmpd_5.7.3+dfsg-1ubuntu4.5_amd64.debLinux
SNMP (Simple Network Management Protocol) server and applications (USN-4471-1) snmpd_5.7.3+dfsg-1.8ubuntu3.5_i386.debLinux
SNMP (Simple Network Management Protocol) server and applications (USN-4471-1) snmpd_5.7.3+dfsg-1.8ubuntu3.5_amd64.debLinux
SNMP (Simple Network Management Protocol) server and applications (USN-4471-1) libsnmp30_5.7.3+dfsg-1ubuntu4.5_i386.debLinux
SNMP (Simple Network Management Protocol) server and applications (USN-4471-1) libsnmp30_5.7.3+dfsg-1ubuntu4.5_amd64.debLinux
SNMP (Simple Network Management Protocol) server and applications (USN-4471-1) libsnmp30_5.7.3+dfsg-1.8ubuntu3.5_i386.debLinux
SNMP (Simple Network Management Protocol) server and applications (USN-4471-1) libsnmp30_5.7.3+dfsg-1.8ubuntu3.5_amd64.debLinux
SNMP (Simple Network Management Protocol) server and applications (USN-4471-1) libsnmp35_5.8+dfsg-2ubuntu2.3_i386.debLinux
SNMP (Simple Network Management Protocol) server and applications (USN-4471-1) libsnmp35_5.8+dfsg-2ubuntu2.3_amd64.debLinux
SNMP (Simple Network Management Protocol) server and applications (USN-4471-1) libsnmp-base_5.8+dfsg-2ubuntu2.3_all.debLinux
SNMP (Simple Network Management Protocol) server and applications (USN-4471-1) libsnmp-base_5.7.3+dfsg-1ubuntu4.5_all.debLinux
SNMP (Simple Network Management Protocol) server and applications (USN-4471-1) libsnmp-base_5.7.3+dfsg-1.8ubuntu3.5_all.debLinux
SNMP (Simple Network Management Protocol) server and applications (USN-4471-1) libsnmp-perl_5.8+dfsg-2ubuntu2.3_i386.debLinux
SNMP (Simple Network Management Protocol) server and applications (USN-4471-1) libsnmp-perl_5.8+dfsg-2ubuntu2.3_amd64.debLinux
SNMP (Simple Network Management Protocol) server and applications (USN-4471-1) libsnmp-perl_5.7.3+dfsg-1ubuntu4.5_i386.debLinux
SNMP (Simple Network Management Protocol) server and applications (USN-4471-1) libsnmp-perl_5.7.3+dfsg-1ubuntu4.5_amd64.debLinux
SNMP (Simple Network Management Protocol) server and applications (USN-4471-1) libsnmp-perl_5.7.3+dfsg-1.8ubuntu3.5_i386.debLinux
SNMP (Simple Network Management Protocol) server and applications (USN-4471-1) libsnmp-perl_5.7.3+dfsg-1.8ubuntu3.5_amd64.debLinux
(RHSA-2020:5129) net-snmp security update net-snmp-5.5-60.el6_10.2.i686.rpmLinux
(RHSA-2020:5129) net-snmp security update net-snmp-5.5-60.el6_10.2.x86_64.rpmLinux
(RHSA-2020:5129) net-snmp security update net-snmp-devel-5.5-60.el6_10.2.i686.rpmLinux
(RHSA-2020:5129) net-snmp security update net-snmp-devel-5.5-60.el6_10.2.x86_64.rpmLinux
(RHSA-2020:5129) net-snmp security update net-snmp-libs-5.5-60.el6_10.2.i686.rpmLinux
(RHSA-2020:5129) net-snmp security update net-snmp-libs-5.5-60.el6_10.2.x86_64.rpmLinux
(RHSA-2020:5129) net-snmp security update net-snmp-perl-5.5-60.el6_10.2.i686.rpmLinux
(RHSA-2020:5129) net-snmp security update net-snmp-perl-5.5-60.el6_10.2.x86_64.rpmLinux
(RHSA-2020:5129) net-snmp security update net-snmp-python-5.5-60.el6_10.2.i686.rpmLinux
(RHSA-2020:5129) net-snmp security update net-snmp-python-5.5-60.el6_10.2.x86_64.rpmLinux
(RHSA-2020:5129) net-snmp security update net-snmp-utils-5.5-60.el6_10.2.i686.rpmLinux
(RHSA-2020:5129) net-snmp security update net-snmp-utils-5.5-60.el6_10.2.x86_64.rpmLinux
Net-snmp update (ELSA-2020-5129) net-snmp-5.5-60.0.1.el6_10.2.x86_64.rpmLinux
Net-snmp-devel update (ELSA-2020-5129) net-snmp-devel-5.5-60.0.1.el6_10.2.x86_64.rpmLinux
Net-snmp-libs update (ELSA-2020-5129) net-snmp-libs-5.5-60.0.1.el6_10.2.x86_64.rpmLinux
Net-snmp-perl update (ELSA-2020-5129) net-snmp-perl-5.5-60.0.1.el6_10.2.x86_64.rpmLinux
Net-snmp-python update (ELSA-2020-5129) net-snmp-python-5.5-60.0.1.el6_10.2.x86_64.rpmLinux
Net-snmp-utils update (ELSA-2020-5129) net-snmp-utils-5.5-60.0.1.el6_10.2.x86_64.rpmLinux
Net-snmp update (ELSA-2020-5129) net-snmp-5.5-60.0.1.el6_10.2.i686.rpmLinux
Net-snmp-devel update (ELSA-2020-5129) net-snmp-devel-5.5-60.0.1.el6_10.2.i686.rpmLinux
Net-snmp-libs update (ELSA-2020-5129) net-snmp-libs-5.5-60.0.1.el6_10.2.i686.rpmLinux
Net-snmp-perl update (ELSA-2020-5129) net-snmp-perl-5.5-60.0.1.el6_10.2.i686.rpmLinux
Net-snmp-python update (ELSA-2020-5129) net-snmp-python-5.5-60.0.1.el6_10.2.i686.rpmLinux
Net-snmp-utils update (ELSA-2020-5129) net-snmp-utils-5.5-60.0.1.el6_10.2.i686.rpmLinux
(RHSA-2020:5350) net-snmp security update net-snmp-5.7.2-49.el7_9.1.x86_64.rpmLinux
(RHSA-2020:5350) net-snmp security update net-snmp-agent-libs-5.7.2-49.el7_9.1.i686.rpmLinux
(RHSA-2020:5350) net-snmp security update net-snmp-agent-libs-5.7.2-49.el7_9.1.x86_64.rpmLinux
(RHSA-2020:5350) net-snmp security update net-snmp-devel-5.7.2-49.el7_9.1.i686.rpmLinux
(RHSA-2020:5350) net-snmp security update net-snmp-devel-5.7.2-49.el7_9.1.x86_64.rpmLinux
(RHSA-2020:5350) net-snmp security update net-snmp-gui-5.7.2-49.el7_9.1.x86_64.rpmLinux
(RHSA-2020:5350) net-snmp security update net-snmp-libs-5.7.2-49.el7_9.1.i686.rpmLinux
(RHSA-2020:5350) net-snmp security update net-snmp-libs-5.7.2-49.el7_9.1.x86_64.rpmLinux
(RHSA-2020:5350) net-snmp security update net-snmp-perl-5.7.2-49.el7_9.1.x86_64.rpmLinux
(RHSA-2020:5350) net-snmp security update net-snmp-python-5.7.2-49.el7_9.1.x86_64.rpmLinux
(RHSA-2020:5350) net-snmp security update net-snmp-sysvinit-5.7.2-49.el7_9.1.x86_64.rpmLinux
(RHSA-2020:5350) net-snmp security update net-snmp-utils-5.7.2-49.el7_9.1.x86_64.rpmLinux
(RHSA-2020:5480) net-snmp security and bug fix update net-snmp-5.8-18.el8_3.1.x86_64.rpmLinux
(RHSA-2020:5480) net-snmp security and bug fix update net-snmp-agent-libs-5.8-18.el8_3.1.i686.rpmLinux
(RHSA-2020:5480) net-snmp security and bug fix update net-snmp-agent-libs-5.8-18.el8_3.1.x86_64.rpmLinux
(RHSA-2020:5480) net-snmp security and bug fix update net-snmp-debugsource-5.8-18.el8_3.1.i686.rpmLinux
(RHSA-2020:5480) net-snmp security and bug fix update net-snmp-debugsource-5.8-18.el8_3.1.x86_64.rpmLinux
(RHSA-2020:5480) net-snmp security and bug fix update net-snmp-devel-5.8-18.el8_3.1.i686.rpmLinux
(RHSA-2020:5480) net-snmp security and bug fix update net-snmp-devel-5.8-18.el8_3.1.x86_64.rpmLinux
(RHSA-2020:5480) net-snmp security and bug fix update net-snmp-libs-5.8-18.el8_3.1.i686.rpmLinux
(RHSA-2020:5480) net-snmp security and bug fix update net-snmp-libs-5.8-18.el8_3.1.x86_64.rpmLinux
(RHSA-2020:5480) net-snmp security and bug fix update net-snmp-perl-5.8-18.el8_3.1.x86_64.rpmLinux
(RHSA-2020:5480) net-snmp security and bug fix update net-snmp-utils-5.8-18.el8_3.1.x86_64.rpmLinux
Net-snmp update (ELSA-2020-5480) net-snmp-5.8-18.el8_3.1.x86_64.rpmLinux
Net-snmp-agent-libs update (ELSA-2020-5480) net-snmp-agent-libs-5.8-18.el8_3.1.i686.rpmLinux
Net-snmp-agent-libs update (ELSA-2020-5480) net-snmp-agent-libs-5.8-18.el8_3.1.x86_64.rpmLinux
Net-snmp-devel update (ELSA-2020-5480) net-snmp-devel-5.8-18.el8_3.1.i686.rpmLinux
Net-snmp-devel update (ELSA-2020-5480) net-snmp-devel-5.8-18.el8_3.1.x86_64.rpmLinux
Net-snmp-libs update (ELSA-2020-5480) net-snmp-libs-5.8-18.el8_3.1.i686.rpmLinux
Net-snmp-libs update (ELSA-2020-5480) net-snmp-libs-5.8-18.el8_3.1.x86_64.rpmLinux
Net-snmp-perl update (ELSA-2020-5480) net-snmp-perl-5.8-18.el8_3.1.x86_64.rpmLinux
Net-snmp-utils update (ELSA-2020-5480) net-snmp-utils-5.8-18.el8_3.1.x86_64.rpmLinux
(CESA-2020:5350) net-snmp security update net-snmp-5.7.2-49.el7_9.1.x86_64.rpmLinux
(CESA-2020:5350) net-snmp security update net-snmp-agent-libs-5.7.2-49.el7_9.1.i686.rpmLinux
(CESA-2020:5350) net-snmp security update net-snmp-agent-libs-5.7.2-49.el7_9.1.x86_64.rpmLinux
(CESA-2020:5350) net-snmp security update net-snmp-devel-5.7.2-49.el7_9.1.i686.rpmLinux
(CESA-2020:5350) net-snmp security update net-snmp-devel-5.7.2-49.el7_9.1.x86_64.rpmLinux
(CESA-2020:5350) net-snmp security update net-snmp-gui-5.7.2-49.el7_9.1.x86_64.rpmLinux
(CESA-2020:5350) net-snmp security update net-snmp-libs-5.7.2-49.el7_9.1.i686.rpmLinux
(CESA-2020:5350) net-snmp security update net-snmp-libs-5.7.2-49.el7_9.1.x86_64.rpmLinux
(CESA-2020:5350) net-snmp security update net-snmp-perl-5.7.2-49.el7_9.1.x86_64.rpmLinux
(CESA-2020:5350) net-snmp security update net-snmp-python-5.7.2-49.el7_9.1.x86_64.rpmLinux
(CESA-2020:5350) net-snmp security update net-snmp-sysvinit-5.7.2-49.el7_9.1.x86_64.rpmLinux
(CESA-2020:5350) net-snmp security update net-snmp-utils-5.7.2-49.el7_9.1.x86_64.rpmLinux
SUSE-SU-2022:0030-1(SUSE Linux Enterprise Server 12-SP5 ) libsnmp30-5.7.3-6.9.1.x86_64.rpmLinux
SUSE-SU-2022:0030-1(SUSE Linux Enterprise Server 12-SP5 ) libsnmp30-32bit-5.7.3-6.9.1.x86_64.rpmLinux
SUSE-SU-2022:0030-1(SUSE Linux Enterprise Server 12-SP5 ) libsnmp30-debuginfo-5.7.3-6.9.1.x86_64.rpmLinux
SUSE-SU-2022:0030-1(SUSE Linux Enterprise Server 12-SP5 ) libsnmp30-debuginfo-32bit-5.7.3-6.9.1.x86_64.rpmLinux
SUSE-SU-2022:0030-1(SUSE Linux Enterprise Server 12-SP5 ) net-snmp-5.7.3-6.9.1.x86_64.rpmLinux
SUSE-SU-2022:0030-1(SUSE Linux Enterprise Server 12-SP5 ) net-snmp-debuginfo-5.7.3-6.9.1.x86_64.rpmLinux
SUSE-SU-2022:0030-1(SUSE Linux Enterprise Server 12-SP5 ) net-snmp-debugsource-5.7.3-6.9.1.x86_64.rpmLinux
SUSE-SU-2022:0030-1(SUSE Linux Enterprise Server 12-SP5 ) perl-SNMP-5.7.3-6.9.1.x86_64.rpmLinux
SUSE-SU-2022:0030-1(SUSE Linux Enterprise Server 12-SP5 ) perl-SNMP-debuginfo-5.7.3-6.9.1.x86_64.rpmLinux
SUSE-SU-2022:0030-1(SUSE Linux Enterprise Server 12-SP5 ) snmp-mibs-5.7.3-6.9.1.x86_64.rpmLinux
(RHSA-2020:5350)Important: security update net-snmp-debuginfo-5.7.2-49.el7_9.1.i686.rpmLinux
(RHSA-2020:5350)Important: security update net-snmp-debuginfo-5.7.2-49.el7_9.1.x86_64.rpmLinux
SNMP (Simple Network Management Protocol) server and applications (USN-4471-1) libsnmp-base_5.8+dfsg-2ubuntu2.3_all.debLinux
Improper Privilege Management Vulnerability (CVE-2020-15862)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234