← All CVEs

CVE-2018-18065

medium · 6.5

_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.

6.5
CVSS
17.2%
EPSS (exploit prob.)
97th
EPSS percentile
2018-10-08
Published

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-476

Affected products

VendorProductAffected versions
net-snmpnet-snmp< 5.8
debiandebian_linux9.0
canonicalubuntu_linux12.04
canonicalubuntu_linux14.04
canonicalubuntu_linux16.04
canonicalubuntu_linux18.04
canonicalubuntu_linux18.10
netappcloud_backupall versions
netapphyper_converged_infrastructureall versions
netappstoragegrid_webscaleall versions
netappdata_ontapall versions
netappe-series_santricity_os_controller>= 11.0, <= 11.5
netappsolidfire_element_osall versions
paloaltonetworkspan-os<= 7.1.22
paloaltonetworkspan-os>= 7.1.23, <= 8.0.15
paloaltonetworkspan-os>= 8.0.16, <= 8.1.6

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-18065