Astracon Information for VU#107186

Multiple vulnerabilities in SNMPv1 trap handling


Not Affected

Vendor Statement

      The Astracon Stinger NetConnect is safe against the vulnerability reported by VU#107186. The Stinger NetConnect processes SNMP responses only. Since the trap demon is never invoked, the Stinger NetConnect will never receive a trap; it is always safe.

      The Stinger NetConnect doesn't accept SNMP requests, but can send SNMP version 1 or version 3 requests. By configuring the NetConnect to use only SNMP version 3, the vulnerabilities caused when using SNMP version 1 in the network will be avoided.

      In order to ensure safety against the vulnerability reported by VU#854306 and VU#107186, the test cases at were executed, with no adverse effect on the NetConnect. The Stinger NetConnect passed all of the test cases.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Vendor References



The CERT/CC has no additional comments at this time.

If you have feedback, comments, or additional information about this vulnerability, please send us email.