{"id":9490,"date":"2025-12-26T10:03:48","date_gmt":"2025-12-26T10:03:48","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/26\/net-snmp-vulnerability-enables-buffer-overflow-and-the-daemon-to-crash\/"},"modified":"2025-12-26T10:03:48","modified_gmt":"2025-12-26T10:03:48","slug":"net-snmp-vulnerability-enables-buffer-overflow-and-the-daemon-to-crash","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/26\/net-snmp-vulnerability-enables-buffer-overflow-and-the-daemon-to-crash\/","title":{"rendered":"Net-SNMP Vulnerability Enables Buffer Overflow and the Daemon to Crash"},"content":{"rendered":"<p>    Net-SNMP Vulnerability Enables Buffer Overflow and the Daemon to Crash<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A new critical vulnerability affecting the Net-SNMP software suite has been disclosed, posing a significant risk to network infrastructure worldwide.<\/p>\n<p>Tracked as\u00a0CVE-2025-68615, this security flaw allows remote attackers to trigger a <a href=\"https:\/\/cybersecuritynews.com\/fortios-buffer-overflow-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">buffer overflow<\/a>, leading to a service crash or potentially a more severe system compromise.<\/p>\n<p>The vulnerability resides specifically in the\u00a0snmptrapd\u00a0daemon, which receives and processes SNMP trap messages.<\/p>\n<p>Net-SNMP is a widely deployed protocol suite used for <a href=\"https:\/\/cybersecuritynews.com\/snmp-monitoring-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">monitoring<\/a> network devices such as routers, switches, and servers.<\/p>\n<p>Because this software is widely used in enterprise environments, the scope of this threat is extensive. The issue stems from improper handling of incoming packets.<\/p>\n<p>According to GitHub advisories, a threat actor can exploit this by sending a \u201cspecially crafted packet\u201d to a vulnerable\u00a0snmptrapd\u00a0instance.<\/p>\n<p>When the <a href=\"https:\/\/cybersecuritynews.com\/new-daemon-ex-plist-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">daemon<\/a> attempts to process this malformed data, it triggers a buffer overflow.<\/p>\n<p>While the primary description notes that this causes the daemon to crash (<a href=\"https:\/\/cybersecuritynews.com\/6-new-critical-vulnerabilities-found-in-dlink-routers\/\" target=\"_blank\" rel=\"noreferrer noopener\">Denial-of-Service<\/a>), the severity metrics suggest a more serious possibility.<\/p>\n<p>The vulnerability has been assigned a\u00a0CVSS score of 9.8 (Critical). The metrics indicate \u201cHigh\u201d impact on Confidentiality, Integrity, and Availability.<\/p>\n<p>In cybersecurity terms, a buffer overflow with these ratings often implies that an attacker could do more than crash the server; they might be able to execute arbitrary code remotely (<a href=\"https:\/\/cybersecuritynews.com\/n8n-automation-platform-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">RCE<\/a>).<\/p>\n<p>Effectively taking control of the affected system without needing a password or user interaction. A researcher discovered the vulnerability in collaboration with the\u00a0Trend Micro <a href=\"https:\/\/cybersecuritynews.com\/windows-lnk-vulnerability-abused-by-hackers\/\" target=\"_blank\" rel=\"noreferrer noopener\">Zero Day<\/a> Initiative.<\/p>\n<p>The maintainers of Net-SNMP have released patches to address this flaw. Administrators are urged to upgrade immediately to\u00a0version 5.9.5\u00a0or\u00a05.10. pre2.<\/p>\n<p><span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">According to the\u00a0<a href=\"https:\/\/github.com\/net-snmp\/net-snmp\/security\/advisories\/GHSA-4389-rwqf-q9gq\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">advisory<\/a> published\u00a0for organizations unable to apply patches immediately, the primary workaround is network segmentation.<\/span> <\/p>\n<p>SNMP ports should never be exposed to the public internet. Ensuring that <a href=\"https:\/\/cybersecuritynews.com\/cisco-firewalls-vulnerability-exploited\/\" target=\"_blank\" rel=\"noreferrer noopener\">firewalls<\/a> block external access to the\u00a0snmptrapd\u00a0port effectively mitigates the risk of remote exploitation.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/net-snmp-vulnerability\/\">Net-SNMP Vulnerability Enables Buffer Overflow and the Daemon to Crash<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/net-snmp-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Net-SNMP Vulnerability Enables Buffer Overflow and the Daemon to Crash A new critical vulnerability affecting the Net-SNMP software suite has been disclosed, posing a significant risk to network infrastructure worldwide. Tracked as\u00a0CVE-2025-68615, this security flaw allows remote attackers to trigger a buffer overflow, leading to a service crash or potentially a more severe system compromise. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-9490","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9490"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9490"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9490\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9490"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9490"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9490"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}