cbcvebase.
CVE-2008-0960
published 2008-06-10

CVE-2008-0960: SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and…

PriorityP270critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
68.79%
99.3th percentile
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.

Affected

11 ranges
VendorProductVersion rangeFixed in
debiannet-snmp< net-snmp 5.4.1~dfsg-8.1 (bookworm)net-snmp 5.4.1~dfsg-8.1 (bookworm)
junipersession_and_resource_control
junipersession_and_resource_control
junipersrc_pe
junipersrc_pe
net-snmpnet-snmp>= 0 < 5.4.1~dfsg-8.15.4.1~dfsg-8.1
net-snmpnet-snmp>= 0 < 5.4.1~dfsg-8.15.4.1~dfsg-8.1
net-snmpnet-snmp>= 0 < 5.4.1~dfsg-8.15.4.1~dfsg-8.1
net-snmpnet-snmp>= 0 < 5.4.1~dfsg-8.15.4.1~dfsg-8.1
vmwareesxi
vmwarevmware_workstation

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/5790.tgz
port161/udp
  • Detect SNMPv3 authentication bypass attempts by inspecting HMAC length field in SNMPv3 packets; a value of 1 (single byte HMAC) in the msgAuthenticationParameters field is a strong indicator of exploitation.
  • Only SNMPv3 traffic is affected; SNMPv1, v2, and v2c are not impacted. Focus detection efforts exclusively on SNMPv3 message processing.
  • On Cisco devices, cross-reference against Bug IDs CSCsf04754, CSCsf30109, CSCsf29976, CSCsq62662 to identify vulnerable software trains.
  • Alert on SNMPv3 packets where the attacker spoofs an authenticated message; the flaw allows configuration changes or information disclosure without valid credentials.
  • ·The SNMP server is an optional service disabled by default on Cisco products; exposure only exists if SNMPv3 has been explicitly enabled.
  • ·The vulnerability is architectural: the HMAC length is client-controlled, meaning any SNMPv3 implementation that trusts the client-supplied length value is potentially vulnerable regardless of vendor.

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_cisco10.0CRITICAL
vendor_debian10.0MEDIUM
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.