CVE-2018-18066: Null Pointer Dereference
snmpoidcompare in snmplib/snmpapi.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-18066?
CVE-2018-18066 is a vulnerability in Net-SNMP before 5.8 that allows an unauthenticated attacker to remotely crash the instance via a crafted UDP packet, resulting in a denial of service.
How severe is CVE-2018-18066?
CVE-2018-18066 has a severity rating of 7.5 (high).
Which software versions are affected by CVE-2018-18066?
Net-SNMP versions before 5.8, Netapp Cloud Backup, Netapp Hyper Converged Infrastructure, NetApp StorageGRID Webscale, NetApp Data ONTAP, NetApp E-Series SANtricity OS Controller (versions 11.0 to 11.5), and Netapp Solidfire Element Os are affected by CVE-2018-18066.
How can an unauthenticated attacker exploit CVE-2018-18066?
An unauthenticated attacker can exploit CVE-2018-18066 by sending a crafted UDP packet to the vulnerable instance.
Are there any fixes or patches for CVE-2018-18066?
It is recommended to update Net-SNMP to version 5.8 or later to mitigate the vulnerability.