← Back to CVE List
Vulnerability Intelligence Report

CVE-2008-0960

SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.

No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:68.79%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
cisco catos 7.1.1, 7.3.1, 7.4.1, 8.3
cisco cisco_ios 12.0, 12.1, 12.2, 12.3, 12.4
cisco ios 10.0, 11.0, 11.1, 11.3, 12.2
cisco ios_xr 2.0, 3.0, 3.2, 3.3, 3.4, 3.5, 3.6, 3.7
cisco nx_os 4.0, 4.0.1, 4.0.2
ecos_sourceware ecos 1.1, 1.2.1, 1.3.1, 2.0
net-snmp net_snmp 5.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4, 5.0.5, 5.0.6, 5.0.7, 5.0.8, 5.0.9, 5.1, 5.1.1, 5.1.2, 5.2, 5.3, 5.3.0.1, 5.4
sun solaris 10.0
sun sunos 5.10
cisco ace_10_6504_bundle_with_4_gbps_throughput all
cisco ace_10_6509_bundle_with_8_gbps_throughput all
cisco ace_10_service_module all
cisco ace_20_6504_bundle_with__4gbps_throughput all
cisco ace_20_6509_bundle_with_8gbps_throughput all
cisco ace_20_service_module all
cisco ace_4710 all
cisco ace_xml_gateway 5.2, 6.0
cisco mds_9120 all
cisco mds_9124 all
cisco mds_9134 all
cisco mds_9140 all
ingate ingate_firewall 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.4.0, 2.4.1, 2.5.0, 2.6.0, 2.6.1, 3.0.2, 3.1.0, 3.1.1, 3.1.3, 3.1.4, 3.2.0, 3.2.1, 3.2.2, 3.3.1, 4.1.0, 4.1.3, 4.2.1, 4.2.2, 4.2.3, 4.3.1, 4.4.1, 4.4.2, 4.5.1, 4.5.2, 4.6.0, 4.6.1, 4.6.2
ingate ingate_siparator 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.4.0, 2.4.1, 2.5.0, 2.6.0, 2.6.1, 3.0.2, 3.1.0, 3.1.1, 3.1.3, 3.1.4, 3.2.0, 3.2.1, 3.2.2, 3.3.1, 4.1.0, 4.1.3, 4.2.1, 4.2.2, 4.2.3, 4.3.1, 4.3.4, 4.4.1, 4.4.2, 4.5.1, 4.5.2, 4.6.0, 4.6.1, 4.6.2
juniper session_and_resource_control 1.0, 2.0
juniper src_pe 1.0, 2.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
68.790%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCERT/CC · CERT · USA
Reserved2008-02-25T00:00:00
Published2008-06-10T18:00:00
Patch Date2008-06-09
Last Updated2024-08-07T08:01:40

LINK COPIED TO CLIPBOARD