Re: CVE for this issue?

Bill Fenner <[email protected]>
Newsgroups gmane.network.net-snmp.devel
Message-ID <CAF4SogYy8UzenOOMMZRBq=UdNScZvrBLLCuR=EWwj0vZmZhNYg@mail.gmail.com>
On Mon, Jan 29, 2018 at 8:19 AM, Magnus Fromreide <[email protected]>
wrote:

> On Mon, Jan 29, 2018 at 10:53:31AM -0300, Pedro Barbosa wrote:
> > Hi,
> >
> > Does anyone know which CVE regards to this issue?
> >
> > https://github.com/rapid7/metasploit-framework/pull/9396
> >
> > /This exploit module exploits the SNMP write access configuration
> ability of
> > SNMP-EXTEND-MIB to configure MIB extensions and lead to remote code
> > execution.
>
> Well, I do not know of any CVE number but I will happily admit that it
> looks like a catastrohy waiting to happen.
>

Do people really give read/write SNMP access to untrusted parties?

  Bill

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot

_______________________________________________
Net-snmp-coders mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/net-snmp-coders
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.