Back to Database
Status published
High
CVE-2020-15862
Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE...
Vulnerability Description
Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-15862
Credits & Attribution
No credits recorded in the NVD database.
References
- https://salsa.debian.org/debian/net-snmp/-/commit/fad8725402752746daf0a751dcff19eb6aeab52e
- https://github.com/net-snmp/net-snmp/commit/77f6c60f57dba0aaea5d8ef1dd94bcd0c8e6d205
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=965166
- https://security-tracker.debian.org/tracker/CVE-2020-15862
- https://security.gentoo.org/glsa/202008-12
- https://usn.ubuntu.com/4471-1/
- https://security.netapp.com/advisory/ntap-20200904-0001/
More from net-snmp
View All →CVE-2025-68615
Net-SNMP snmptrapd crash
Critical
9.8
CVE-2022-44793
handle_ipv6IpForwarding in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.4.3 through 5.9.3 has a...
Unknown
0
CVE-2022-44792
handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a...
Unknown
0
CVE-2022-24810
net-snmp: A malformed OID in a SET to the nsVacmAccessTable can cause a NULL pointer dereference.
Medium
6.5
CVE-2022-24809
net-snmp: A malformed OID in a SET request to NET-SNMP-AGENT-MIB::nsLogTable can cause a NULL pointer dereference
Medium
6.5
Affected Vendor
net-snmp
View all reports →Affected Software
net-snmp, ubuntu linux, cloud backup, hci management node, smi-s provider, solidfire
Vulnerable Versions:
0, 12.04, 14.04, 16.04, 18.04, 20.04
Timeline
Official Publish:
August 19th, 2020
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.