Use of uninitialized resource in Mini SNMP daemon - #VU146783

 

Use of uninitialized resource in Mini SNMP daemon - #VU146783

Published: September 2, 2026


Vulnerability identifier: #VU146783
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-908
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to uninitialized memory exposure in the SNMP OID encoding and varbind reply generation logic when processing specially crafted SNMP requests with non-minimal OID sub-identifiers. A remote attacker can send a specially crafted request for an absent OID to disclose sensitive information.

On UDP, the leaked data can contain a previous response sent to another client, including echoed community strings. On TCP, a later request on the same connection leaks only that connection\'s previous response.


Affected software

Mini SNMP daemon

Remediation

Install security update from vendor's website.

Mini SNMP daemon - update to 2.1

External References

Related Security Bulletins