- User Since
- Sep 2 2021, 11:08 AM (80 w, 5 d)
Nov 5 2021
Alternatively, can you provide the contact information of NET-SNMP's PRIST? I can also contact him for vulnerability disclosure.
Yes, I also believe that this crash exists in all current versions of NET-SNMP. And I also found this vulnerability in the source code of the latest version of Net-SNMP( version 5.9.1), and I compiled and installed net-SNMP on Ubuntu to duplicate this vulnerability. But I can't find the contact information of NET-SNMP. It seems that only the cooperative manufacturer can contact him. Can you negotiate with them to disclose this vulnerability?
Oct 8 2021
@dmbaturin Did you get my email? If not, please let me know and I will send it again
Sep 27 2021
By the way, the SNMPD service of the router will not restart automatically. After the SNMP service is attacked, the SNMP service cannot be restored even if the device is restarted, which may be an inappropriate implementation.
I have a question. If you confirm the existence of the vulnerability, can you report to the NET-SNMP vendor and apply for a CVE number?
I have sent the POC of the vulnerability to [email protected]
By the way, The password of the compressed package is HGkasjgJFYL261.
Hello, I have found three vulnerabilities in V1.2.7, one of which can also be reproduced in V1.3, please continue to check the other versions, I will send all three POCs to your email, thank you for your work.
Sep 26 2021
May I ask where I can submit poC? Do you provide an email address or upload files here?
Sep 17 2021
Sep 7 2021
May I ask whether the vulnerability report should be made public here or submitted to which mailbox? Will a PGP public key be provided to encrypt sensitive information?
Sep 5 2021
Here is the screenshot of vulnerability reproduction.
I tried to reproduce the vulnerability we found on v1.2.7 version of VyOS and debug the vulnerability, hoping to provide you with a detailed vulnerability report.
Sep 4 2021
Hello, I can't find the latest version of VyOS on the Internet. Could you please provide a mirror image to my mailbox? I'll validate any bugs I find. My email address is [email protected]
Sep 2 2021
These vulnerabilities can cause the EFFECT of SNMP service Dos,