Description
In NextX Duo's snmp addon versions before 6.4.4, a part of the Eclipse Foundation ThreadX, an attacker could cause an out-of-bound read by a crafted SNMPv3 security parameters.
Problem types
CWE-1285: Improper Validation of Specified Index, Position, or Offset in Input
Product status
Any version before 6.4.4
Credits
ekleezg
References
github.com/...etxduo/security/advisories/GHSA-v474-mv4g-v8cx