CVE-2015-5621: exploitation status and patch state
CVE-2015-5621 · CVSS 7.5 HIGH · EPSS 40%
The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.
Is CVE-2015-5621 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 40%.
Public exploit code: proof of concept.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2015-5621
PlainSec has not published a story about this CVE.