CVE-2008-0960
published 2008-06-10CVE-2008-0960: SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and…
PriorityP270critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
68.79%
99.3th percentile
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | net-snmp | < net-snmp 5.4.1~dfsg-8.1 (bookworm) | net-snmp 5.4.1~dfsg-8.1 (bookworm) |
| juniper | session_and_resource_control | — | — |
| juniper | session_and_resource_control | — | — |
| juniper | src_pe | — | — |
| juniper | src_pe | — | — |
| net-snmp | net-snmp | >= 0 < 5.4.1~dfsg-8.1 | 5.4.1~dfsg-8.1 |
| net-snmp | net-snmp | >= 0 < 5.4.1~dfsg-8.1 | 5.4.1~dfsg-8.1 |
| net-snmp | net-snmp | >= 0 < 5.4.1~dfsg-8.1 | 5.4.1~dfsg-8.1 |
| net-snmp | net-snmp | >= 0 < 5.4.1~dfsg-8.1 | 5.4.1~dfsg-8.1 |
| vmware | esxi | — | — |
| vmware | vmware_workstation | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect SNMPv3 authentication bypass attempts by inspecting HMAC length field in SNMPv3 packets; a value of 1 (single byte HMAC) in the msgAuthenticationParameters field is a strong indicator of exploitation. ↗
- →Only SNMPv3 traffic is affected; SNMPv1, v2, and v2c are not impacted. Focus detection efforts exclusively on SNMPv3 message processing. ↗
- →On Cisco devices, cross-reference against Bug IDs CSCsf04754, CSCsf30109, CSCsf29976, CSCsq62662 to identify vulnerable software trains. ↗
- →Alert on SNMPv3 packets where the attacker spoofs an authenticated message; the flaw allows configuration changes or information disclosure without valid credentials. ↗
- ·The SNMP server is an optional service disabled by default on Cisco products; exposure only exists if SNMPv3 has been explicitly enabled. ↗
- ·The vulnerability is architectural: the HMAC length is client-controlled, meaning any SNMPv3 implementation that trusts the client-supplied length value is potentially vulnerable regardless of vendor. ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_cisco10.0CRITICAL
vendor_debian10.0MEDIUM
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Net-SNMP vulnerabilities
vendor_ubuntu·2008-12-03·CVSS 10.0
CVE-2008-0960 [CRITICAL] Net-SNMP vulnerabilities
Title: Net-SNMP vulnerabilities
Summary: Net-SNMP vulnerabilities
Wes Hardaker discovered that the SNMP service did not correctly validate
HMAC authentication requests. An unauthenticated remote attacker
could send specially crafted SNMPv3 traffic with a valid username
and gain access to the user's views without a valid authentication
passphrase. (CVE-2008-0960)
John Kortink discovered that the Net-SNMP Perl module did not correctly
check the size of returned values. If a user or automated system were
tricked into querying a malicious SNMP server, the application using
the Perl module could be made to crash, leading to a denial of service.
This did not affect Ubuntu 8.10. (CVE-2008-2292)
It was discovered that the SNMP service did not correctly handle large
GETBULK requests. If an unau
VMware
Updated ESX packages for libxml2, ucd-snmp, libtiff
vendor_vmware·2008-10-31·CVSS 6.5
CVE-2008-0960 [MEDIUM] Updated ESX packages for libxml2, ucd-snmp, libtiff
VMSA-2008-0017: Updated ESX packages for libxml2, ucd-snmp, libtiff
a. Updated ESX Service Console package libxml2 A denial of service flaw was found in the way libxml2 processes certain content. If an application that is linked against libxml2 processes malformed XML content, the XML content might cause the application to stop responding. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2008-3281 to this issue. Additionally the following was also fixed, but was missing in the security advisory. A heap-based buffer overflow flaw was found in the way libxml2 handled long XML entity names. If an application linked against libxml2 processed untrusted malformed XML content, it could cause the application to crash or, possibly, execute arbitrary code.
Cisco
SNMP Version 3 Authentication Vulnerabilities
vendor_cisco·2008-06-10·CVSS 10.0
CVE-2008-0960 [CRITICAL] SNMP Version 3 Authentication Vulnerabilities
SNMP Version 3 Authentication Vulnerabilities
Multiple Cisco products contain either of two authentication
vulnerabilities in the Simple Network Management Protocol version 3 (SNMPv3)
feature. These vulnerabilities can be exploited when processing a malformed
SNMPv3 message. These vulnerabilities could allow the disclosure of network
information or may enable an attacker to perform configuration changes to
vulnerable devices. The SNMP server is an optional service that is disabled by
default in Cisco products. Only SNMPv3 is impacted by these vulnerabilities.
Workarounds are available for mitigating the impact of the vulnerabilities
described in this document.
Note: SNMP versions 1, 2 and 2c are not impacted by these vulnerabilities.
The United States Computer Emergency Response Team (U
Juniper
CVE-2008-0960: SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Ses
vendor_juniper·2008-06-10·CVSS 10.0
CVE-2008-0960 [CRITICAL] CWE-287 CVE-2008-0960: SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Ses
CVE-2008-0960: SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.
Red Hat
net-snmp SNMPv3 authentication bypass (VU#877044)
vendor_redhat·2008-06-09·CVSS 10.0
CVE-2008-0960 [CRITICAL] net-snmp SNMPv3 authentication bypass (VU#877044)
net-snmp SNMPv3 authentication bypass (VU#877044)
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.
Debian
CVE-2008-0960: net-snmp - SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3....
vendor_debian·2008·CVSS 10.0
CVE-2008-0960 [CRITICAL] CVE-2008-0960: net-snmp - SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3....
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.
Scope: local
bookworm: resolved (fixed in 5.4.1~dfsg-8.1)
bullseye: resolved (fixed in 5.4.1~dfsg-8.1)
forky: re
Cisco
SNMP Version 3 Authentication Vulnerabilities
vendor_cisco
CVE-2008-0960 SNMP Version 3 Authentication Vulnerabilities
CVE-2008-0960: SNMP Version 3 Authentication Vulnerabilities
Multiple Cisco products contain either of two authentication vulnerabilities in the Simple Network Management Protocol version 3 (SNMPv3) feature. These vulnerabilities can be exploited when processing a malformed SNMPv3 message. These vulnerabilities could allow the disclosure of network information or may enable an attacker to perform configuration changes to vulnerable devices. The SNMP server is an optional service that is disabled by default in Cisco products. Only SNMPv3 is impacted by these vulnerabilities.
Bug IDs: CSCsf04754, CSCsf04754, CSCsf30109, CSCsf29976, CSCsq62662
GHSA
GHSA-xmp9-m365-hwwg: SNMPv3 HMAC verification in (1) Net-SNMP 5
ghsa_unreviewed·2022-05-01
CVE-2008-0960 [HIGH] CWE-287 GHSA-xmp9-m365-hwwg: SNMPv3 HMAC verification in (1) Net-SNMP 5
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.
OSV
CVE-2008-0960: SNMPv3 HMAC verification in (1) Net-SNMP 5
osv·2008-06-10·CVSS 10.0
CVE-2008-0960 [CRITICAL] CVE-2008-0960: SNMPv3 HMAC verification in (1) Net-SNMP 5
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.
No detection rules found.
http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.htmlhttp://lists.ingate.com/pipermail/productinfo/2008/000021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-08/msg00000.htmlhttp://marc.info/?l=bugtraq&m=127730470825399&w=2http://rhn.redhat.com/errata/RHSA-2008-0528.htmlhttp://secunia.com/advisories/30574http://secunia.com/advisories/30596http://secunia.com/advisories/30612http://secunia.com/advisories/30615http://secunia.com/advisories/30626http://secunia.com/advisories/30647http://secunia.com/advisories/30648http://secunia.com/advisories/30665http://secunia.com/advisories/30802http://secunia.com/advisories/31334http://secunia.com/advisories/31351http://secunia.com/advisories/31467http://secunia.com/advisories/31568http://secunia.com/advisories/32664http://secunia.com/advisories/33003http://secunia.com/advisories/35463http://security.gentoo.org/glsa/glsa-200808-02.xmlhttp://securityreason.com/securityalert/3933http://sourceforge.net/forum/forum.php?forum_id=833770http://sourceforge.net/tracker/index.php?func=detail&aid=1989089&group_id=12694&atid=456380http://sunsolve.sun.com/search/document.do?assetkey=1-26-238865-1http://support.apple.com/kb/HT2163http://support.avaya.com/elmodocs2/security/ASA-2008-282.htmhttp://www.cisco.com/warp/public/707/cisco-sa-20080610-snmpv3.shtmlhttp://www.debian.org/security/2008/dsa-1663http://www.kb.cert.org/vuls/id/878044http://www.kb.cert.org/vuls/id/CTAR-7FBS8Qhttp://www.kb.cert.org/vuls/id/MIMG-7ETS5Zhttp://www.kb.cert.org/vuls/id/MIMG-7ETS87http://www.mandriva.com/security/advisories?name=MDVSA-2008:118http://www.ocert.org/advisories/ocert-2008-006.htmlhttp://www.openwall.com/lists/oss-security/2008/06/09/1http://www.redhat.com/support/errata/RHSA-2008-0529.htmlhttp://www.securityfocus.com/archive/1/493218/100/0/threadedhttp://www.securityfocus.com/archive/1/497962/100/0/threadedhttp://www.securityfocus.com/bid/29623http://www.securitytracker.com/id?1020218http://www.ubuntu.com/usn/usn-685-1http://www.us-cert.gov/cas/techalerts/TA08-162A.htmlhttp://www.vmware.com/security/advisories/VMSA-2008-0013.htmlhttp://www.vmware.com/security/advisories/VMSA-2008-0017.htmlhttp://www.vupen.com/english/advisories/2008/1787/referenceshttp://www.vupen.com/english/advisories/2008/1788/referenceshttp://www.vupen.com/english/advisories/2008/1797/referenceshttp://www.vupen.com/english/advisories/2008/1800/referenceshttp://www.vupen.com/english/advisories/2008/1801/referenceshttp://www.vupen.com/english/advisories/2008/1836/referenceshttp://www.vupen.com/english/advisories/2008/1981/referenceshttp://www.vupen.com/english/advisories/2008/2361http://www.vupen.com/english/advisories/2008/2971http://www.vupen.com/english/advisories/2009/1612https://bugzilla.redhat.com/show_bug.cgi?id=447974https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10820https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5785https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6414https://www.exploit-db.com/exploits/5790https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00363.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-June/msg00380.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-June/msg00459.htmlhttp://lists.apple.com/archives/security-announce/2008//Jun/msg00002.htmlhttp://lists.ingate.com/pipermail/productinfo/2008/000021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-08/msg00000.htmlhttp://marc.info/?l=bugtraq&m=127730470825399&w=2http://rhn.redhat.com/errata/RHSA-2008-0528.htmlhttp://secunia.com/advisories/30574http://secunia.com/advisories/30596http://secunia.com/advisories/30612http://secunia.com/advisories/30615http://secunia.com/advisories/30626http://secunia.com/advisories/30647http://secunia.com/advisories/30648http://secunia.com/advisories/30665http://secunia.com/advisories/30802http://secunia.com/advisories/31334http://secunia.com/advisories/31351http://secunia.com/advisories/31467http://secunia.com/advisories/31568http://secunia.com/advisories/32664http://secunia.com/advisories/33003http://secunia.com/advisories/35463http://security.gentoo.org/glsa/glsa-200808-02.xmlhttp://securityreason.com/securityalert/3933http://sourceforge.net/forum/forum.php?forum_id=833770http://sourceforge.net/tracker/index.php?func=detail&aid=1989089&group_id=12694&atid=456380http://sunsolve.sun.com/search/document.do?assetkey=1-26-238865-1http://support.apple.com/kb/HT2163http://support.avaya.com/elmodocs2/security/ASA-2008-282.htmhttp://www.cisco.com/warp/public/707/cisco-sa-20080610-snmpv3.shtmlhttp://www.debian.org/security/2008/dsa-1663http://www.kb.cert.org/vuls/id/878044http://www.kb.cert.org/vuls/id/CTAR-7FBS8Qhttp://www.kb.cert.org/vuls/id/MIMG-7ETS5Zhttp://www.kb.cert.org/vuls/id/MIMG-7ETS87http://www.mandriva.com/security/advisories?name=MDVSA-2008:118http://www.ocert.org/advisories/ocert-2008-006.html
+ 28 more references
2008-06-10
Published