VDB

CISA-2015-5621

CISA-2015-5621 PUBLISHED CVSS 7.5 HIGH

Reported by mitre · Published August 19, 2015

The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
n/an/an/a
n/an/an/a, *

Timeline

  • Aug 19, 2015 CVE Published
  • Dec 4, 2025 CVE Updated
  • Mar 26, 2026 Distribution Patch
  • Mar 26, 2026 Distribution Patch
  • Mar 26, 2026 Security Advisory
  • Mar 26, 2026 Security Advisory

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›