CVE-2008-2214 describes a stack-based buffer overflow in the Network Manager component of Castle Rock Computing SNMPc versions 7.1 and earlier. This critical vulnerability, with a CVSS score of 10.0, allows remote, unauthenticated attackers to trigger a denial of service or execute arbitrary code by sending a specially crafted SNMP TRAP packet containing an excessively long community string. While not listed in CISA's KEV catalog, a proof-of-concept exploit is publicly available on ExploitDB, indicating its exploitability. Despite its age and high severity, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.1CPE matchmatch criteria | cpe:2.3:a:castle_rock:snmpc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.