SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
Ace 10 6504 Bundle With 4 Gbps Throughput
Subscribe
Ace 10 6509 Bundle With 8 Gbps Throughput
Subscribe
Ace 10 Service Module
Subscribe
Ace 20 6504 Bundle With 4gbps Throughput
Subscribe
Ace 20 6509 Bundle With 8gbps Throughput
Subscribe
Ace 20 Service Module
Subscribe
Ace 4710
Subscribe
Ace Xml Gateway
Subscribe
Catos
Subscribe
Cisco Ios
Subscribe
Ios
Subscribe
Ios Xr
Subscribe
Mds 9120
Subscribe
Mds 9124
Subscribe
Mds 9134
Subscribe
Mds 9140
Subscribe
Nx Os
Subscribe
|
|
Ecos Sourceware
Subscribe
|
Ecos
Subscribe
|
|
Ingate
Subscribe
|
|
|
Juniper
Subscribe
|
|
|
Net-snmp
Subscribe
|
Net Snmp
Subscribe
|
|
Redhat
Subscribe
|
|
|
Sun
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1663-1 | New net-snmp packages fix several vulnerabilities |
Ubuntu USN |
USN-685-1 | Net-SNMP vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-08-07T08:01:40.150Z
Reserved: 2008-02-25T00:00:00
Link: CVE-2008-0960
No data.
Status : Deferred
Published: 2008-06-10T18:32:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2008-0960
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Ubuntu USN