CVE-2025-55087: Medium severity NextX Duo snmp addon vulnerability
In NextX Duo's snmp addon versions before 6.4.4, a part of the Eclipse Foundation ThreadX, an attacker could cause an out-of-bound read by a crafted SNMPv3 security parameters.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NextX Duo snmp addon (Eclipse Foundation ThreadX)to a version that resolves this vulnerability.Fixed in 6.4.4
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55087?
CVE-2025-55087 is a high-severity vulnerability affecting versions of the NextX Duo snmp addon prior to 6.4.4.
How do I fix CVE-2025-55087?
To fix CVE-2025-55087, upgrade the NextX Duo snmp addon to version 6.4.4 or later.
What type of vulnerability is CVE-2025-55087?
CVE-2025-55087 is an out-of-bounds read vulnerability caused by crafted SNMPv3 security parameters.
Which software is affected by CVE-2025-55087?
CVE-2025-55087 affects the NextX Duo snmp addon versions prior to 6.4.4 and the Eclipse Foundation ThreadX.
Can CVE-2025-55087 be exploited remotely?
Yes, CVE-2025-55087 can potentially be exploited remotely through crafted SNMPv3 requests.