CVE-2015-8100: Infoleak
Published Nov 10, 2015
·Updated
The net-snmp package in OpenBSD through 5.8 uses 0644 permissions for snmpd.conf, which allows local users to obtain sensitive community information by reading this file.
Affected Software
1 affected component
Net-SNMP Net-SNMP<=5.8
Event History
Nov 10, 2015
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8100?
CVE-2015-8100 has been classified as a medium severity vulnerability due to its potential for information disclosure.
2
How do I fix CVE-2015-8100?
To mitigate CVE-2015-8100, change the permissions of the snmpd.conf file to restrict access to authorized users only.
3
What systems are affected by CVE-2015-8100?
CVE-2015-8100 affects systems running the net-snmp package in OpenBSD versions up to 5.8.
4
What type of vulnerability is CVE-2015-8100?
CVE-2015-8100 is an information disclosure vulnerability that allows local users to read sensitive configuration information.
5
Who can exploit CVE-2015-8100?
CVE-2015-8100 can be exploited by local users who have access to the system where the vulnerable version of net-snmp is installed.