SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.

Project Subscriptions

Vendors Products
Ace 10 6504 Bundle With 4 Gbps Throughput Subscribe
Ace 10 6509 Bundle With 8 Gbps Throughput Subscribe
Ace 10 Service Module Subscribe
Ace 20 6504 Bundle With 4gbps Throughput Subscribe
Ace 20 6509 Bundle With 8gbps Throughput Subscribe
Ace 20 Service Module Subscribe
Ace 4710 Subscribe
Ace Xml Gateway Subscribe
Cisco Ios Subscribe
Mds 9120 Subscribe
Mds 9124 Subscribe
Mds 9134 Subscribe
Mds 9140 Subscribe
Ecos Sourceware Subscribe
Ingate Firewall Subscribe
Ingate Siparator Subscribe
Juniper Subscribe
Session And Resource Control Subscribe
Net-snmp Subscribe
Net Snmp Subscribe
Enterprise Linux Subscribe
Rhel Eus Subscribe
Advisories
Source ID Title
Debian DSA Debian DSA DSA-1663-1 New net-snmp packages fix several vulnerabilities
Ubuntu USN Ubuntu USN USN-685-1 Net-SNMP vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html cve-icon cve-icon
http://lists.ingate.com/pipermail/productinfo/2008/000021.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00000.html cve-icon cve-icon
http://marc.info/?l=bugtraq&m=127730470825399&w=2 cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2008-0528.html cve-icon cve-icon
http://secunia.com/advisories/30574 cve-icon cve-icon
http://secunia.com/advisories/30596 cve-icon cve-icon
http://secunia.com/advisories/30612 cve-icon cve-icon
http://secunia.com/advisories/30615 cve-icon cve-icon
http://secunia.com/advisories/30626 cve-icon cve-icon
http://secunia.com/advisories/30647 cve-icon cve-icon
http://secunia.com/advisories/30648 cve-icon cve-icon
http://secunia.com/advisories/30665 cve-icon cve-icon
http://secunia.com/advisories/30802 cve-icon cve-icon
http://secunia.com/advisories/31334 cve-icon cve-icon
http://secunia.com/advisories/31351 cve-icon cve-icon
http://secunia.com/advisories/31467 cve-icon cve-icon
http://secunia.com/advisories/31568 cve-icon cve-icon
http://secunia.com/advisories/32664 cve-icon cve-icon
http://secunia.com/advisories/33003 cve-icon cve-icon
http://secunia.com/advisories/35463 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200808-02.xml cve-icon cve-icon
http://securityreason.com/securityalert/3933 cve-icon cve-icon
http://sourceforge.net/forum/forum.php?forum_id=833770 cve-icon cve-icon
http://sourceforge.net/tracker/index.php?func=detail&aid=1989089&group_id=12694&atid=456380 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-238865-1 cve-icon cve-icon
http://support.apple.com/kb/HT2163 cve-icon cve-icon
http://support.avaya.com/elmodocs2/security/ASA-2008-282.htm cve-icon cve-icon
http://www.cisco.com/warp/public/707/cisco-sa-20080610-snmpv3.shtml cve-icon cve-icon
http://www.debian.org/security/2008/dsa-1663 cve-icon cve-icon
http://www.kb.cert.org/vuls/id/878044 cve-icon cve-icon
http://www.kb.cert.org/vuls/id/CTAR-7FBS8Q cve-icon cve-icon
http://www.kb.cert.org/vuls/id/MIMG-7ETS5Z cve-icon cve-icon
http://www.kb.cert.org/vuls/id/MIMG-7ETS87 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2008:118 cve-icon cve-icon
http://www.ocert.org/advisories/ocert-2008-006.html cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2008/06/09/1 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0529.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/493218/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/497962/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/29623 cve-icon cve-icon
http://www.securitytracker.com/id?1020218 cve-icon cve-icon
http://www.ubuntu.com/usn/usn-685-1 cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA08-162A.html cve-icon cve-icon
http://www.vmware.com/security/advisories/VMSA-2008-0013.html cve-icon cve-icon
http://www.vmware.com/security/advisories/VMSA-2008-0017.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/1787/references cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/1788/references cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/1797/references cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/1800/references cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/1801/references cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/1836/references cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/1981/references cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/2361 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/2971 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/1612 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=447974 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2008-0960 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10820 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5785 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6414 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2008-0960 cve-icon
https://www.exploit-db.com/exploits/5790 cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00363.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00380.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00459.html cve-icon cve-icon
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2024-08-07T08:01:40.150Z

Reserved: 2008-02-25T00:00:00

Link: CVE-2008-0960

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2008-06-10T18:32:00.000

Modified: 2025-04-09T00:30:58.490

Link: CVE-2008-0960

cve-icon Redhat

Severity : Moderate

Publid Date: 2008-06-09T00:00:00Z

Links: CVE-2008-0960 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses