Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.
[
{
"source": "https://github.com/net-snmp/net-snmp/commit/77f6c60f57dba0aaea5d8ef1dd94bcd0c8e6d205",
"id": "CVE-2020-15862-04e19943",
"deprecated": false,
"target": {
"function": "handle_nsExtendConfigTable",
"file": "agent/mibgroup/agent/extend.c"
},
"signature_version": "v1",
"digest": {
"length": 9271.0,
"function_hash": "168126842589556839519669983730365362130"
},
"signature_type": "Function"
},
{
"source": "https://github.com/net-snmp/net-snmp/commit/77f6c60f57dba0aaea5d8ef1dd94bcd0c8e6d205",
"id": "CVE-2020-15862-47f67391",
"deprecated": false,
"target": {
"function": "fixExec2Error",
"file": "agent/mibgroup/agent/extend.c"
},
"signature_version": "v1",
"digest": {
"length": 821.0,
"function_hash": "324934863496545396025090335580678431555"
},
"signature_type": "Function"
},
{
"source": "https://github.com/net-snmp/net-snmp/commit/77f6c60f57dba0aaea5d8ef1dd94bcd0c8e6d205",
"id": "CVE-2020-15862-5385aeff",
"deprecated": false,
"target": {
"file": "agent/mibgroup/agent/extend.c"
},
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"160382126734202674681144535403338919409",
"292824773818941776052985057530600565348",
"117093767884005896506214374923466371893",
"153887981556162111395467978566793611856",
"304548919929739460042427222392484181457",
"252983075219966496628509281461955283348",
"158242383511248042541185602283552251988",
"98122535300492461348015372959760569968",
"84141191864820422749253422037217897627",
"280175792542161621203133292429721249072",
"121001552494923370436879991271021038415",
"3598910393246450005704482474149929215",
"319352373915069118550616144745180834572",
"290887612190499742534011183377797667151",
"280553204632066801854360105056994083320",
"30350696284143358276391654732140777753",
"124520032205378816472060548262952644942",
"302478858594664857332311134752383174524",
"234635746856935271453069637068018831103",
"111656735251291391883623057449194990850",
"108127288387902992133428563749627954087",
"120781652379473419448725747206302201239",
"275293827951289342513748652240830857287",
"123147406844998894071053026392993388614",
"55432564476577231908975284108535574993",
"302478858594664857332311134752383174524",
"84824618504714555464659388230927545211"
]
},
"signature_type": "Line"
}
]