SNMP Incorrect Access Control... CVE 2017-5135

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

In DEFCON 24 IoT Village i gave a talk about the danger of SNMP write properties enabled devices in IoT, police patrols, ambulances and other in “critical mission vehicles” were affected in that research. In December 2016 with a colleague from Argentina (Ezequiel Fernandez) we decided to “fuzz” again the SNMP protocol in the internet but this time using different combinations in the community string, for example what if we test which nodes from the internet using SNMP random values in the community string like “root” “admin” “user” will respond to our requests? In order to recap quickly the SNMP basics, we know there are 3 ways to authenticate the client and requests in the remote SNMP device, SNMP version 1 & 2 use a human-readable string datatype value called “community string” (usually public or private) in SNMP version 3 you have the option to use a user, password and authentication methods. Also, all information like oids ,traps and other stuff is stored in the management...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息