CVE-2018-18066: Net-SNMP
High severity, CVSS 7.5. EPSS: 3.6% chance of exploitation in the next 30 days.
snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
Affected products
- Net-SNMP Net-SNMP: before 5.8 (fixed in 5.8)
- Netapp Cloud Backup: affected versions not specified
- Netapp Data Ontap: affected versions not specified
- Netapp E-Series Santricity OS Controller: from 11.0, up to and including 11.5
- Netapp Hyper Converged Infrastructure: affected versions not specified
- Netapp Solidfire Element OS: affected versions not specified
- Netapp Storagegrid Webscale: affected versions not specified
Published 2018-10-08. Last modified 2026-06-17.