Description
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1663-1 | New net-snmp packages fix several vulnerabilities |
Ubuntu USN |
USN-685-1 | Net-SNMP vulnerabilities |
References
History
No history.
Subscriptions
Cisco
Subscribe
Ace 10 6504 Bundle With 4 Gbps Throughput
Subscribe
Ace 10 6509 Bundle With 8 Gbps Throughput
Subscribe
Ace 10 Service Module
Subscribe
Ace 20 6504 Bundle With 4gbps Throughput
Subscribe
Ace 20 6509 Bundle With 8gbps Throughput
Subscribe
Ace 20 Service Module
Subscribe
Ace 4710
Subscribe
Ace Xml Gateway
Subscribe
Catos
Subscribe
Cisco Ios
Subscribe
Ios
Subscribe
Ios Xr
Subscribe
Mds 9120
Subscribe
Mds 9124
Subscribe
Mds 9134
Subscribe
Mds 9140
Subscribe
Nx Os
Subscribe
Ecos Sourceware
Subscribe
Ecos
Subscribe
Ingate
Subscribe
Ingate Firewall
Subscribe
Ingate Siparator
Subscribe
Juniper
Subscribe
Session And Resource Control
Subscribe
Src Pe
Subscribe
Net-snmp
Subscribe
Net Snmp
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Rhel Eus
Subscribe
Sun
Subscribe
Solaris
Subscribe
Sunos
Subscribe
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-08-07T08:01:40.150Z
Reserved: 2008-02-25T00:00:00.000Z
Link: CVE-2008-0960
No data.
Status : Deferred
Published: 2008-06-10T18:32:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2008-0960
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Ubuntu USN