CVE-2006-6305: High severity net-snmp net-snmp vulnerability
Published Dec 6, 2006
·Updated
Unspecified vulnerability in Net-SNMP 5.3 before 5.3.0.1, when configured using the rocommunity or rouser snmpd.conf tokens, causes Net-SNMP to grant write access to users or communities that only have read-only access.
Affected Software
1 affected component
Net-SNMP Net-SNMP=5.3
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 6, 2006
CVE Published
10:28 PM
Data Sourced
via NVD·10:28 PM
RemedyDescriptionSeverityAffected Software
Dec 7, 2006
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-6305?
CVE-2006-6305 is considered a medium severity vulnerability.
2
How do I fix CVE-2006-6305?
To fix CVE-2006-6305, upgrade to Net-SNMP version 5.3.0.1 or later.
3
What types of configurations are affected by CVE-2006-6305?
CVE-2006-6305 affects configurations using the rocommunity or rouser tokens in snmpd.conf.
4
Who is impacted by CVE-2006-6305?
Users and communities granted read-only access may inadvertently gain write access due to CVE-2006-6305.
5
Is CVE-2006-6305 present in newer versions of Net-SNMP?
CVE-2006-6305 is not present in Net-SNMP versions later than 5.3.0.1.