HIGH · 10.0

CVE-2008-0960

SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 thr...

Vulnerability Description

SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoCatos7.1.1
CiscoCisco Ios12.0
CiscoIos10.0
CiscoIos Xr2.0
CiscoNx Os4.0
Ecos SourcewareEcos1.1
Net-SnmpNet Snmp5.0
SunSolaris10.0
SunSunos5.10
CiscoAce 10 6504 Bundle With 4 Gbps ThroughputAll versions
CiscoAce 10 6509 Bundle With 8 Gbps ThroughputAll versions
CiscoAce 10 Service ModuleAll versions
CiscoAce 20 6504 Bundle With 4Gbps ThroughputAll versions
CiscoAce 20 6509 Bundle With 8Gbps ThroughputAll versions
CiscoAce 20 Service ModuleAll versions
CiscoAce 4710All versions
CiscoAce Xml Gateway5.2
CiscoMds 9120All versions
CiscoMds 9124All versions
CiscoMds 9134All versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-0960?

CVE-2008-0960 is a vulnerability with a CVSS score of 10.0 (HIGH). SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 thr...

How severe is CVE-2008-0960?

CVE-2008-0960 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-0960?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Catos, Cisco Cisco Ios, Cisco Ios, Cisco Ios Xr, Cisco Nx Os.