CWE
287
Advisory Published
CVE Published
Updated

CVE-2008-0960

First published: Thu May 22 2008(Updated: )

CERT has told us of an authentication bypass flaw in Net-SNMP and UCD-SNMP. According to net-snmp: "The quick technical summary is that the SNMPv3 packet contains a truncated HMAC authentication code. The author that wrote the code very very long ago to check that HMAC code used the length of the packet's version of the HMAC code to do the check. Thus if you send a single byte HMAC code, it'll only check it against the first byte of HMAC output. Thus it's fairly easy to spoof an authenticated SNMPv3 packet."

Credit: cret@cert.org

Affected SoftwareAffected VersionHow to fix
Cisco CatOS=7.1.1
Cisco CatOS=7.3.1
Cisco CatOS=7.4.1
Cisco CatOS=8.3
Cisco Cisco Ios=12.0-s
Cisco Cisco Ios=12.0-sy
Cisco Cisco Ios=12.1-e
Cisco Cisco Ios=12.2-ewa
Cisco Cisco Ios=12.2-jk
Cisco Cisco Ios=12.2-sb
Cisco Cisco Ios=12.2-sg
Cisco Cisco Ios=12.2-sga
Cisco Cisco Ios=12.2-sra
Cisco Cisco Ios=12.2-srb
Cisco Cisco Ios=12.2-src
Cisco Cisco Ios=12.2-sxb
Cisco Cisco Ios=12.2-sxd
Cisco Cisco Ios=12.2-sxf
Cisco Cisco Ios=12.2-zl
Cisco Cisco Ios=12.2-zy
Cisco Cisco Ios=12.3
Cisco Cisco Ios=12.3-b
Cisco Cisco Ios=12.3-ja
Cisco Cisco Ios=12.3-jeb
Cisco Cisco Ios=12.3-jk
Cisco Cisco Ios=12.3-jl
Cisco Cisco Ios=12.3-jx
Cisco Cisco Ios=12.3-t
Cisco Cisco Ios=12.3-xa
Cisco Cisco Ios=12.3-xg
Cisco Cisco Ios=12.3-xi
Cisco Cisco Ios=12.3-xk
Cisco Cisco Ios=12.3-xr
Cisco Cisco Ios=12.3-yf
Cisco Cisco Ios=12.3-yi
Cisco Cisco Ios=12.3-yt
Cisco Cisco Ios=12.3-yx
Cisco Cisco Ios=12.4
Cisco Cisco Ios=12.4-t
Cisco Cisco Ios=12.4-xa
Cisco Cisco Ios=12.4-xc
Cisco Cisco Ios=12.4-xd
Cisco Cisco Ios=12.4-xe
Cisco Cisco Ios=12.4-xj
Cisco Cisco Ios=12.4-xw
Cisco IOS=10.0
Cisco IOS=11.0
Cisco IOS=11.1
Cisco IOS=11.3
Cisco IOS=12.2
Cisco IOS XR=2.0
Cisco IOS XR=3.0
Cisco IOS XR=3.2
Cisco IOS XR=3.3
Cisco IOS XR=3.4
Cisco IOS XR=3.5
Cisco IOS XR=3.6
Cisco IOS XR=3.7
Cisco Nx Os=4.0
Cisco Nx Os=4.0.1-a
Cisco Nx Os=4.0.2
Ecos Sourceware Ecos=1.1
Ecos Sourceware Ecos=1.2.1
Ecos Sourceware Ecos=1.3.1
Ecos Sourceware Ecos=2.0
Ecos Sourceware Ecos=2.0-b1
Net-snmp Net Snmp=5.0
Net-snmp Net Snmp=5.0.1
Net-snmp Net Snmp=5.0.2
Net-snmp Net Snmp=5.0.3
Net-snmp Net Snmp=5.0.4
Net-snmp Net Snmp=5.0.5
Net-snmp Net Snmp=5.0.6
Net-snmp Net Snmp=5.0.7
Net-snmp Net Snmp=5.0.8
Net-snmp Net Snmp=5.0.9
Net-snmp Net Snmp=5.1
Net-snmp Net Snmp=5.1.1
Net-snmp Net Snmp=5.1.2
Net-snmp Net Snmp=5.2
Net-snmp Net Snmp=5.3
Net-snmp Net Snmp=5.3.0.1
Net-snmp Net Snmp=5.4
Sun Solaris=10.0-unkown
Sun SunOS=5.10
Cisco Ace 10 6504 Bundle With 4 Gbps Throughput
Cisco Ace 10 6509 Bundle With 8 Gbps Throughput
Cisco Ace 10 Service Module
Cisco Ace 20 6504 Bundle With 4gbps Throughput
Cisco Ace 20 6509 Bundle With 8gbps Throughput
Cisco Ace 20 Service Module
Cisco ACE 4710
Cisco ACE XML Gateway=5.2
Cisco ACE XML Gateway=6.0
Cisco Mds 9120
Cisco Mds 9124
Cisco Mds 9134
Cisco Mds 9140
Ingate Ingate Firewall=2.2.0
Ingate Ingate Firewall=2.2.1
Ingate Ingate Firewall=2.2.2
Ingate Ingate Firewall=2.3.0
Ingate Ingate Firewall=2.4.0
Ingate Ingate Firewall=2.4.1
Ingate Ingate Firewall=2.5.0
Ingate Ingate Firewall=2.6.0
Ingate Ingate Firewall=2.6.1
Ingate Ingate Firewall=3.0.2
Ingate Ingate Firewall=3.1.0
Ingate Ingate Firewall=3.1.1
Ingate Ingate Firewall=3.1.3
Ingate Ingate Firewall=3.1.4
Ingate Ingate Firewall=3.2.0
Ingate Ingate Firewall=3.2.1
Ingate Ingate Firewall=3.2.2
Ingate Ingate Firewall=3.3.1
Ingate Ingate Firewall=4.1.0
Ingate Ingate Firewall=4.1.3
Ingate Ingate Firewall=4.2.1
Ingate Ingate Firewall=4.2.2
Ingate Ingate Firewall=4.2.3
Ingate Ingate Firewall=4.3.1
Ingate Ingate Firewall=4.4.1
Ingate Ingate Firewall=4.4.2
Ingate Ingate Firewall=4.5.1
Ingate Ingate Firewall=4.5.2
Ingate Ingate Firewall=4.6.0
Ingate Ingate Firewall=4.6.1
Ingate Ingate Firewall=4.6.2
Ingate Ingate Siparator=2.2.0
Ingate Ingate Siparator=2.2.1
Ingate Ingate Siparator=2.2.2
Ingate Ingate Siparator=2.3.0
Ingate Ingate Siparator=2.4.0
Ingate Ingate Siparator=2.4.1
Ingate Ingate Siparator=2.5.0
Ingate Ingate Siparator=2.6.0
Ingate Ingate Siparator=2.6.1
Ingate Ingate Siparator=3.0.2
Ingate Ingate Siparator=3.1.0
Ingate Ingate Siparator=3.1.1
Ingate Ingate Siparator=3.1.3
Ingate Ingate Siparator=3.1.4
Ingate Ingate Siparator=3.2.0
Ingate Ingate Siparator=3.2.1
Ingate Ingate Siparator=3.2.2
Ingate Ingate Siparator=3.3.1
Ingate Ingate Siparator=4.1.0
Ingate Ingate Siparator=4.1.3
Ingate Ingate Siparator=4.2.1
Ingate Ingate Siparator=4.2.2
Ingate Ingate Siparator=4.2.3
Ingate Ingate Siparator=4.3.1
Ingate Ingate Siparator=4.3.4
Ingate Ingate Siparator=4.4.1
Ingate Ingate Siparator=4.4.2
Ingate Ingate Siparator=4.5.1
Ingate Ingate Siparator=4.5.2
Ingate Ingate Siparator=4.6.0
Ingate Ingate Siparator=4.6.1
Ingate Ingate Siparator=4.6.2
Juniper Session and Resource Control=1.0
Juniper Session and Resource Control=2.0
Juniper Src Pe=1.0
Juniper Src Pe=2.0

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Reference Links

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203