CVE-2018-18066: Net-SNMP

High severity, CVSS 7.5. EPSS: 3.6% chance of exploitation in the next 30 days.

snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.

Affected products

  • Net-SNMP Net-SNMP: before 5.8 (fixed in 5.8)
  • Netapp Cloud Backup: affected versions not specified
  • Netapp Data Ontap: affected versions not specified
  • Netapp E-Series Santricity OS Controller: from 11.0, up to and including 11.5
  • Netapp Hyper Converged Infrastructure: affected versions not specified
  • Netapp Solidfire Element OS: affected versions not specified
  • Netapp Storagegrid Webscale: affected versions not specified

Published 2018-10-08. Last modified 2026-06-17.