← Back to browse · API

CVE-2015-5621

Severity
HIGH
CVSS
7.5
EPSS
0.40002
Risk score
44.0
CISA KEV
No
PoC
No
Published
2015-08-19
Modified
2025-12-04
First seen
2026-08-07
Aliases
EUVD-2015-5573, GHSA-W7CC-JV4P-QCCR
Products
n/a:n/a n/a
Sources
euvd EUVD-2015-5573

Description

The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.

References