CVE-2024-55547: Remote Command Execution via SNMP
Published Dec 10, 2024
·Updated
SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. This issue affects IAP-420: through 2.01e.
Affected Software
3 affected components
Net-SNMP IAP-420<=2.01e
All of the following
Oringnet Iap-420 Firmware<=2.01e
Oringnet Iap-420
Event History
Dec 10, 2024
CVE Published
via MITRE·04:27 PM
Data Sourced
via MITRE·04:27 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-55547?
CVE-2024-55547 is classified as a critical severity vulnerability due to the potential for command injection.
2
How do I fix CVE-2024-55547?
To mitigate CVE-2024-55547, upgrade the NET-SNMP IAP-420 firmware to a version later than 2.01e.
3
What is the impact of CVE-2024-55547?
The impact of CVE-2024-55547 includes the possibility of an attacker executing arbitrary commands on the affected system.
4
Which software versions are affected by CVE-2024-55547?
CVE-2024-55547 affects NET-SNMP IAP-420 versions up to and including 2.01e.
5
Who is affected by CVE-2024-55547?
Organizations using NET-SNMP IAP-420 devices with firmware version 2.01e or earlier are affected by CVE-2024-55547.