PT-2026-102765 · Azure Rtos · Nextx Duo Snmp Addon
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
NetX Duo SNMP addon (affected versions not specified)
Description
The
nx snmp utility object id get function in the NetX Duo SNMP addon fails to validate the claimed OID data length against the actual buffer size when Basic Encoding Rules (BER) multibyte length encoding is used. A remote attacker can send a crafted SNMP packet with a multibyte OID length that exceeds the available buffer, causing the parser to perform an out-of-bounds read into adjacent heap memory. These bytes are then decoded as OID component values and written into the agent's internal OID string buffer, leading to state corruption. On systems with memory protection, this can crash the SNMP agent thread and cause a denial of service, while on bare metal embedded systems without memory protection, the read may silently corrupt the internal state with heap data.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nextx Duo Snmp Addon