Re: CVE for this issue?
Bill Fenner <[email protected]>
| Newsgroups | gmane.network.net-snmp.devel |
|---|---|
| Message-ID | <CAF4SogYy8UzenOOMMZRBq=UdNScZvrBLLCuR=EWwj0vZmZhNYg@mail.gmail.com> |
On Mon, Jan 29, 2018 at 8:19 AM, Magnus Fromreide <[email protected]> wrote: > On Mon, Jan 29, 2018 at 10:53:31AM -0300, Pedro Barbosa wrote: > > Hi, > > > > Does anyone know which CVE regards to this issue? > > > > https://github.com/rapid7/metasploit-framework/pull/9396 > > > > /This exploit module exploits the SNMP write access configuration > ability of > > SNMP-EXTEND-MIB to configure MIB extensions and lead to remote code > > execution. > > Well, I do not know of any CVE number but I will happily admit that it > looks like a catastrohy waiting to happen. > Do people really give read/write SNMP access to untrusted parties? Bill ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot _______________________________________________ Net-snmp-coders mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/net-snmp-coders