CVE Database
/

CVE-2008-0960

Back to search

CVE-2008-0960

Published: Jun 10, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.

VendorProductVersions

n/a

n/a

affected
n/a

References

35463
third-party-advisory
x_refsource_SECUNIA
30615
third-party-advisory
x_refsource_SECUNIA
ADV-2008-1787
vdb-entry
x_refsource_VUPEN
30648
third-party-advisory
x_refsource_SECUNIA
32664
third-party-advisory
x_refsource_SECUNIA
ADV-2008-1981
vdb-entry
x_refsource_VUPEN
ADV-2008-1801
vdb-entry
x_refsource_VUPEN
SUSE-SA:2008:039
vendor-advisory
x_refsource_SUSE
31351
third-party-advisory
x_refsource_SECUNIA
ADV-2008-1788
vdb-entry
x_refsource_VUPEN
FEDORA-2008-5215
vendor-advisory
x_refsource_FEDORA
29623
vdb-entry
x_refsource_BID
31334
third-party-advisory
x_refsource_SECUNIA
ADV-2008-2971
vdb-entry
x_refsource_VUPEN
oval:org.mitre.oval:def:10820
vdb-entry
signature
x_refsource_OVAL
oval:org.mitre.oval:def:6414
vdb-entry
signature
x_refsource_OVAL
30626
third-party-advisory
x_refsource_SECUNIA
SSRT080082
vendor-advisory
x_refsource_HP
HPSBMA02439
vendor-advisory
x_refsource_HP
VU#878044
third-party-advisory
x_refsource_CERT-VN
30647
third-party-advisory
x_refsource_SECUNIA
238865
vendor-advisory
x_refsource_SUNALERT
ADV-2008-1836
vdb-entry
x_refsource_VUPEN
33003
third-party-advisory
x_refsource_SECUNIA
ADV-2008-2361
vdb-entry
x_refsource_VUPEN
31568
third-party-advisory
x_refsource_SECUNIA
31467
third-party-advisory
x_refsource_SECUNIA
APPLE-SA-2008-06-30
vendor-advisory
x_refsource_APPLE
DSA-1663
vendor-advisory
x_refsource_DEBIAN
TA08-162A
third-party-advisory
x_refsource_CERT
RHSA-2008:0528
vendor-advisory
x_refsource_REDHAT
3933
third-party-advisory
x_refsource_SREASON
RHSA-2008:0529
vendor-advisory
x_refsource_REDHAT
30612
third-party-advisory
x_refsource_SECUNIA
30802
third-party-advisory
x_refsource_SECUNIA
5790
exploit
x_refsource_EXPLOIT-DB
ADV-2008-1797
vdb-entry
x_refsource_VUPEN
GLSA-200808-02
vendor-advisory
x_refsource_GENTOO
30665
third-party-advisory
x_refsource_SECUNIA
FEDORA-2008-5218
vendor-advisory
x_refsource_FEDORA
FEDORA-2008-5224
vendor-advisory
x_refsource_FEDORA
ADV-2008-1800
vdb-entry
x_refsource_VUPEN
MDVSA-2008:118
vendor-advisory
x_refsource_MANDRIVA
USN-685-1
vendor-advisory
x_refsource_UBUNTU
1020218
vdb-entry
x_refsource_SECTRACK
30596
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:5785
vdb-entry
signature
x_refsource_OVAL
ADV-2009-1612
vdb-entry
x_refsource_VUPEN
30574
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now