PatchSiren cyber security CVE debrief
CVE-2015-5677 Freebsd CVE debrief
CVE-2015-5677 is a local information disclosure issue in FreeBSD's bsnmpd. In affected FreeBSD 9.3, 10.1, and 10.2 systems, the snmpd.config file was world-readable, which could let a local user read the secret key used for SNMP USM authentication. The NVD entry lists the issue as CVSS 5.5 (Medium) with local access, low privileges, and no user interaction required.
- Vendor
- Freebsd
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-07
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-07
- Advisory updated
- 2026-05-13
Who should care
FreeBSD administrators and operators who use bsnmpd, especially on the affected FreeBSD releases 9.3, 10.1, and 10.2. Any environment that relies on SNMP USM credentials stored in snmpd.config should treat this as a credential exposure risk.
Technical summary
NVD describes the vulnerability as a permissions problem on snmpd.config in bsnmpd: the file was world-readable, allowing local users to obtain the secret key for USM authentication by reading it. The NVD record maps the issue to CWE-200 and includes affected CPEs for FreeBSD 9.3, 10.1, and 10.2. The CVSS vector is AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, reflecting confidentiality impact from local file access.
Defensive priority
Medium. The issue is limited to local access, but it directly exposes authentication material and can undermine SNMP security on affected hosts.
Recommended defensive actions
- Apply the FreeBSD vendor advisory for bsnmpd (FreeBSD-SA-16:06.bsnmpd).
- Verify that snmpd.config is not world-readable and that file permissions are restricted to the intended service account and administrators.
- Audit whether bsnmpd is enabled on any affected FreeBSD 9.3, 10.1, or 10.2 systems and remove or disable it if not needed.
- Treat any exposed USM secret key as compromised and rotate or replace affected SNMP credentials.
- Review local access controls on affected hosts, since exploitation requires a local user context.
Evidence notes
The vulnerability description supplied in the CVE states that bsnmpd in FreeBSD 9.3, 10.1, and 10.2 used world-readable permissions on snmpd.config, allowing local users to obtain the secret key for USM authentication. The NVD metadata identifies CWE-200 and the CVSS vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N. NVD reference links include the FreeBSD vendor advisory FreeBSD-SA-16:06.bsnmpd and a third-party advisory at pierrekim.github.io, both provided in the source corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2015-5677 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2015-5677
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2015-5677 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2015-5677
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://pierrekim.github.io/blog/2016-01-15-cve-2015-5677-freebsd-bsnmpd.html
[email protected] - Exploit, Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.freebsd.org/security/advisories/FreeBSD-SA-16:06.bsnmpd.asc
[email protected] - Patch, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.