First published: Tue Nov 10 2015(Updated: )
The net-snmp package in OpenBSD through 5.8 uses 0644 permissions for snmpd.conf, which allows local users to obtain sensitive community information by reading this file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Net-SNMP Agent Libraries | <=5.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8100 has been classified as a medium severity vulnerability due to its potential for information disclosure.
To mitigate CVE-2015-8100, change the permissions of the snmpd.conf file to restrict access to authorized users only.
CVE-2015-8100 affects systems running the net-snmp package in OpenBSD versions up to 5.8.
CVE-2015-8100 is an information disclosure vulnerability that allows local users to read sensitive configuration information.
CVE-2015-8100 can be exploited by local users who have access to the system where the vulnerable version of net-snmp is installed.