CVE-2015-5621: Net-SNMP

High severity, CVSS 7.5. EPSS: 40.9% chance of exploitation in the next 30 days.

The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet.

Affected products

  • Net-SNMP Net-SNMP: up to and including 5.7.2

Published 2015-08-19. Last modified 2026-06-17.