peter bassill · operator
$ cve CVE-2002-1570 JSON

CVE-2002-1570 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 5.7% (pctl 93)

Patch early

A public exploit exists.

Description

Heap-based buffer overflow in snmpnetstat for ucd-snmp 4.2.3 and earlier, and net-snmp, allows remote attackers to execute arbitrary code via multiple getnextrequest PDU messages with conflicting ifindex variables, which cause snmpnetstat to write variable data past the end of an array.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS5.66% — more likely to be exploited than 93% of all CVEs
On CISA KEVno
Public exploityes
Published2003-11-03
Last modified2026-06-16

Affected (1)

VendorProduct
ucd-snmpucd-snmp

Public exploits

SourceTitleDate
exploit-dbNet-SNMP 4.2.3 - snmpnetstat Remote Heap Overflow2002-01-03

References

→ the Explorer  ·  watch your stack  ·  NVD