CVE Vulnerabilities

CVE-2008-0960

Improper Authentication

Published: Jun 10, 2008 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
5.8 MODERATE
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Catos Cisco 7.1.1 (including) 7.1.1 (including)
Catos Cisco 7.3.1 (including) 7.3.1 (including)
Catos Cisco 7.4.1 (including) 7.4.1 (including)
Catos Cisco 8.3 (including) 8.3 (including)
Cisco_ios Cisco 12.0-s (including) 12.0-s (including)
Cisco_ios Cisco 12.0-sy (including) 12.0-sy (including)
Cisco_ios Cisco 12.1-e (including) 12.1-e (including)
Cisco_ios Cisco 12.2-ewa (including) 12.2-ewa (including)
Cisco_ios Cisco 12.2-jk (including) 12.2-jk (including)
Cisco_ios Cisco 12.2-sb (including) 12.2-sb (including)
Cisco_ios Cisco 12.2-sg (including) 12.2-sg (including)
Cisco_ios Cisco 12.2-sga (including) 12.2-sga (including)
Cisco_ios Cisco 12.2-sra (including) 12.2-sra (including)
Cisco_ios Cisco 12.2-srb (including) 12.2-srb (including)
Cisco_ios Cisco 12.2-src (including) 12.2-src (including)
Cisco_ios Cisco 12.2-sxb (including) 12.2-sxb (including)
Cisco_ios Cisco 12.2-sxd (including) 12.2-sxd (including)
Cisco_ios Cisco 12.2-sxf (including) 12.2-sxf (including)
Cisco_ios Cisco 12.2-zl (including) 12.2-zl (including)
Cisco_ios Cisco 12.2-zy (including) 12.2-zy (including)
Cisco_ios Cisco 12.3 (including) 12.3 (including)
Cisco_ios Cisco 12.3-b (including) 12.3-b (including)
Cisco_ios Cisco 12.3-ja (including) 12.3-ja (including)
Cisco_ios Cisco 12.3-jeb (including) 12.3-jeb (including)
Cisco_ios Cisco 12.3-jk (including) 12.3-jk (including)
Cisco_ios Cisco 12.3-jl (including) 12.3-jl (including)
Cisco_ios Cisco 12.3-jx (including) 12.3-jx (including)
Cisco_ios Cisco 12.3-t (including) 12.3-t (including)
Cisco_ios Cisco 12.3-xa (including) 12.3-xa (including)
Cisco_ios Cisco 12.3-xg (including) 12.3-xg (including)
Cisco_ios Cisco 12.3-xi (including) 12.3-xi (including)
Cisco_ios Cisco 12.3-xk (including) 12.3-xk (including)
Cisco_ios Cisco 12.3-xr (including) 12.3-xr (including)
Cisco_ios Cisco 12.3-yf (including) 12.3-yf (including)
Cisco_ios Cisco 12.3-yi (including) 12.3-yi (including)
Cisco_ios Cisco 12.3-yt (including) 12.3-yt (including)
Cisco_ios Cisco 12.3-yx (including) 12.3-yx (including)
Cisco_ios Cisco 12.4 (including) 12.4 (including)
Cisco_ios Cisco 12.4-t (including) 12.4-t (including)
Cisco_ios Cisco 12.4-xa (including) 12.4-xa (including)
Cisco_ios Cisco 12.4-xc (including) 12.4-xc (including)
Cisco_ios Cisco 12.4-xd (including) 12.4-xd (including)
Cisco_ios Cisco 12.4-xe (including) 12.4-xe (including)
Cisco_ios Cisco 12.4-xj (including) 12.4-xj (including)
Cisco_ios Cisco 12.4-xw (including) 12.4-xw (including)
Ios Cisco 10.0 (including) 10.0 (including)
Ios Cisco 11.0 (including) 11.0 (including)
Ios Cisco 11.1 (including) 11.1 (including)
Ios Cisco 11.3 (including) 11.3 (including)
Ios Cisco 12.2 (including) 12.2 (including)
Ios_xr Cisco 2.0 (including) 2.0 (including)
Ios_xr Cisco 3.0 (including) 3.0 (including)
Ios_xr Cisco 3.2 (including) 3.2 (including)
Ios_xr Cisco 3.3 (including) 3.3 (including)
Ios_xr Cisco 3.4 (including) 3.4 (including)
Ios_xr Cisco 3.5 (including) 3.5 (including)
Ios_xr Cisco 3.6 (including) 3.6 (including)
Ios_xr Cisco 3.7 (including) 3.7 (including)
Nx_os Cisco 4.0 (including) 4.0 (including)
Nx_os Cisco 4.0.1-a (including) 4.0.1-a (including)
Nx_os Cisco 4.0.2 (including) 4.0.2 (including)
Ecos Ecos_sourceware 1.1 (including) 1.1 (including)
Ecos Ecos_sourceware 1.2.1 (including) 1.2.1 (including)
Ecos Ecos_sourceware 1.3.1 (including) 1.3.1 (including)
Ecos Ecos_sourceware 2.0 (including) 2.0 (including)
Ecos Ecos_sourceware 2.0-b1 (including) 2.0-b1 (including)
Net_snmp Net-snmp 5.0 (including) 5.0 (including)
Net_snmp Net-snmp 5.0.1 (including) 5.0.1 (including)
Net_snmp Net-snmp 5.0.2 (including) 5.0.2 (including)
Net_snmp Net-snmp 5.0.3 (including) 5.0.3 (including)
Net_snmp Net-snmp 5.0.4 (including) 5.0.4 (including)
Net_snmp Net-snmp 5.0.5 (including) 5.0.5 (including)
Net_snmp Net-snmp 5.0.6 (including) 5.0.6 (including)
Net_snmp Net-snmp 5.0.7 (including) 5.0.7 (including)
Net_snmp Net-snmp 5.0.8 (including) 5.0.8 (including)
Net_snmp Net-snmp 5.0.9 (including) 5.0.9 (including)
Net_snmp Net-snmp 5.1 (including) 5.1 (including)
Net_snmp Net-snmp 5.1.1 (including) 5.1.1 (including)
Net_snmp Net-snmp 5.1.2 (including) 5.1.2 (including)
Net_snmp Net-snmp 5.2 (including) 5.2 (including)
Net_snmp Net-snmp 5.3 (including) 5.3 (including)
Net_snmp Net-snmp 5.3.0.1 (including) 5.3.0.1 (including)
Net_snmp Net-snmp 5.4 (including) 5.4 (including)
Solaris Sun 10.0-unkown (including) 10.0-unkown (including)
Sunos Sun 5.10 (including) 5.10 (including)
Red Hat Enterprise Linux 2.1 RedHat ucd-snmp-0:4.2.5-8.AS21.7 *
Red Hat Enterprise Linux 3 RedHat net-snmp-0:5.0.9-2.30E.24 *
Red Hat Enterprise Linux 4 RedHat net-snmp-0:5.1.2-11.el4_6.11.3 *
Red Hat Enterprise Linux 4.5 Z Stream RedHat net-snmp-0:5.1.2-11.el4_6.11.3 *
Red Hat Enterprise Linux 5 RedHat net-snmp-1:5.3.1-24.el5_2.1 *
Net-snmp Ubuntu dapper *
Net-snmp Ubuntu feisty *
Net-snmp Ubuntu gutsy *
Net-snmp Ubuntu hardy *
Net-snmp Ubuntu intrepid *
Net-snmp Ubuntu upstream *
Ucd-snmp Ubuntu dapper *

Potential Mitigations

References