CVE-2022-44792: Null Pointer Dereference
handleipDefaultTTL in agent/mibgroup/ip-mib/ipscalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker (who has write access) to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-44792?
CVE-2022-44792 is a vulnerability in the Net-SNMP software that allows a remote attacker to crash the instance via a crafted UDP packet, resulting in a Denial of Service.
How severe is CVE-2022-44792?
CVE-2022-44792 has a severity value of 6.5, which is considered medium.
Which software versions are affected by CVE-2022-44792?
Net-SNMP versions 5.8 through 5.9.3 are affected by CVE-2022-44792.
How can I fix CVE-2022-44792?
There is currently no official fix for CVE-2022-44792. It is recommended to update to a version of Net-SNMP that is not affected by this vulnerability, when one becomes available.
Where can I find more information about CVE-2022-44792?
You can find more information about CVE-2022-44792 at the following references: [link1], [link2], [link3].