CVE-2008-0960: Critical severity Cisco CatOS vulnerability

Published May 22, 2008
·
Updated

CERT has told us of an authentication bypass flaw in Net-SNMP and UCD-SNMP.

According to net-snmp:

"The quick technical summary is that the SNMPv3 packet contains a truncated HMAC authentication code. The author that wrote the code very very long ago to check that HMAC code used the length of the packet's version of the HMAC code to do the check. Thus if you send a single byte HMAC code, it'll only check it against the first byte of HMAC output. Thus it's fairly easy to spoof an authenticated SNMPv3 packet."

Other sources

SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.

Affected Software

165 affected components
Cisco CatOS=7.1.1
Cisco CatOS=7.3.1
Cisco CatOS=7.4.1
Cisco CatOS=8.3
Cisco Cisco IOS=12.0-s
Cisco Cisco IOS=12.0-sy
Cisco Cisco IOS=12.1-e
Cisco Cisco IOS=12.2-ewa
Cisco Cisco IOS=12.2-jk
Cisco Cisco IOS=12.2-sb
Cisco Cisco IOS=12.2-sg
Cisco Cisco IOS=12.2-sga
Cisco Cisco IOS=12.2-sra
Cisco Cisco IOS=12.2-srb
Cisco Cisco IOS=12.2-src
Cisco Cisco IOS=12.2-sxb
Cisco Cisco IOS=12.2-sxd
Cisco Cisco IOS=12.2-sxf
Cisco Cisco IOS=12.2-zl
Cisco Cisco IOS=12.2-zy
Cisco Cisco IOS=12.3
Cisco Cisco IOS=12.3-b
Cisco Cisco IOS=12.3-ja
Cisco Cisco IOS=12.3-jeb
Cisco Cisco IOS=12.3-jk
Cisco Cisco IOS=12.3-jl
Cisco Cisco IOS=12.3-jx
Cisco Cisco IOS=12.3-t
Cisco Cisco IOS=12.3-xa
Cisco Cisco IOS=12.3-xg
Cisco Cisco IOS=12.3-xi
Cisco Cisco IOS=12.3-xk
Cisco Cisco IOS=12.3-xr
Cisco Cisco IOS=12.3-yf
Cisco Cisco IOS=12.3-yi
Cisco Cisco IOS=12.3-yt
Cisco Cisco IOS=12.3-yx
Cisco Cisco IOS=12.4
Cisco Cisco IOS=12.4-t
Cisco Cisco IOS=12.4-xa
Cisco Cisco IOS=12.4-xc
Cisco Cisco IOS=12.4-xd
Cisco Cisco IOS=12.4-xe
Cisco Cisco IOS=12.4-xj
Cisco Cisco IOS=12.4-xw
Cisco IOS=10.0
Cisco IOS=11.0
Cisco IOS=11.1
Cisco IOS=11.3
Cisco IOS=12.2
Cisco IOS XR=2.0
Cisco IOS XR=3.0
Cisco IOS XR=3.2
Cisco IOS XR=3.3
Cisco IOS XR=3.4
Cisco IOS XR=3.5
Cisco IOS XR=3.6
Cisco IOS XR=3.7
Cisco Nx Os=4.0
Cisco Nx Os=4.0.1-a
Cisco Nx Os=4.0.2
Ecos Sourceware Ecos=1.1
Ecos Sourceware Ecos=1.2.1
Ecos Sourceware Ecos=1.3.1
Ecos Sourceware Ecos=2.0
Ecos Sourceware Ecos=2.0-b1
Net-SNMP Net Snmp=5.0
Net-SNMP Net Snmp=5.0.1
Net-SNMP Net Snmp=5.0.2
Net-SNMP Net Snmp=5.0.3
Net-SNMP Net Snmp=5.0.4
Net-SNMP Net Snmp=5.0.5
Net-SNMP Net Snmp=5.0.6
Net-SNMP Net Snmp=5.0.7
Net-SNMP Net Snmp=5.0.8
Net-SNMP Net Snmp=5.0.9
Net-SNMP Net Snmp=5.1
Net-SNMP Net Snmp=5.1.1
Net-SNMP Net Snmp=5.1.2
Net-SNMP Net Snmp=5.2
Net-SNMP Net Snmp=5.3
Net-SNMP Net Snmp=5.3.0.1
Net-SNMP Net Snmp=5.4
Sun Solaris=10.0-unkown
Sun SunOS=5.10
Cisco Ace 10 6504 Bundle With 4 Gbps Throughput
Cisco Ace 10 6509 Bundle With 8 Gbps Throughput
Cisco Ace 10 Service Module
Cisco Ace 20 6504 Bundle With 4gbps Throughput
Cisco Ace 20 6509 Bundle With 8gbps Throughput
Cisco Ace 20 Service Module
Cisco ACE 4710
Cisco ACE XML Gateway=5.2
Cisco ACE XML Gateway=6.0
Cisco Mds 9120
Cisco Mds 9124
Cisco Mds 9134
Cisco Mds 9140
Ingate Ingate Firewall=2.2.0
Ingate Ingate Firewall=2.2.1
Ingate Ingate Firewall=2.2.2
Ingate Ingate Firewall=2.3.0
Ingate Ingate Firewall=2.4.0
Ingate Ingate Firewall=2.4.1
Ingate Ingate Firewall=2.5.0
Ingate Ingate Firewall=2.6.0
Ingate Ingate Firewall=2.6.1
Ingate Ingate Firewall=3.0.2
Ingate Ingate Firewall=3.1.0
Ingate Ingate Firewall=3.1.1
Ingate Ingate Firewall=3.1.3
Ingate Ingate Firewall=3.1.4
Ingate Ingate Firewall=3.2.0
Ingate Ingate Firewall=3.2.1
Ingate Ingate Firewall=3.2.2
Ingate Ingate Firewall=3.3.1
Ingate Ingate Firewall=4.1.0
Ingate Ingate Firewall=4.1.3
Ingate Ingate Firewall=4.2.1
Ingate Ingate Firewall=4.2.2
Ingate Ingate Firewall=4.2.3
Ingate Ingate Firewall=4.3.1
Ingate Ingate Firewall=4.4.1
Ingate Ingate Firewall=4.4.2
Ingate Ingate Firewall=4.5.1
Ingate Ingate Firewall=4.5.2
Ingate Ingate Firewall=4.6.0
Ingate Ingate Firewall=4.6.1
Ingate Ingate Firewall=4.6.2
Ingate Ingate SIParator=2.2.0
Ingate Ingate SIParator=2.2.1
Ingate Ingate SIParator=2.2.2
Ingate Ingate SIParator=2.3.0
Ingate Ingate SIParator=2.4.0
Ingate Ingate SIParator=2.4.1
Ingate Ingate SIParator=2.5.0
Ingate Ingate SIParator=2.6.0
Ingate Ingate SIParator=2.6.1
Ingate Ingate SIParator=3.0.2
Ingate Ingate SIParator=3.1.0
Ingate Ingate SIParator=3.1.1
Ingate Ingate SIParator=3.1.3
Ingate Ingate SIParator=3.1.4
Ingate Ingate SIParator=3.2.0
Ingate Ingate SIParator=3.2.1
Ingate Ingate SIParator=3.2.2
Ingate Ingate SIParator=3.3.1
Ingate Ingate SIParator=4.1.0
Ingate Ingate SIParator=4.1.3
Ingate Ingate SIParator=4.2.1
Ingate Ingate SIParator=4.2.2
Ingate Ingate SIParator=4.2.3
Ingate Ingate SIParator=4.3.1
Ingate Ingate SIParator=4.3.4
Ingate Ingate SIParator=4.4.1
Ingate Ingate SIParator=4.4.2
Ingate Ingate SIParator=4.5.1
Ingate Ingate SIParator=4.5.2
Ingate Ingate SIParator=4.6.0
Ingate Ingate SIParator=4.6.1
Ingate Ingate SIParator=4.6.2
Juniper Session and Resource Control=1.0
Juniper Session and Resource Control=2.0
Juniper Src Pe=1.0
Juniper Src Pe=2.0

Event History

May 22, 2008
Data Sourced
via Red Hat·06:17 PM
DescriptionSeverityAffected Software
Jun 10, 2008
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
06:32 PM
DescriptionWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2008-0960?

The CVE-2008-0960 vulnerability is considered critical due to its potential for authentication bypass.

2

How do I fix CVE-2008-0960?

To fix CVE-2008-0960, upgrade to the latest version of Net-SNMP or UCD-SNMP that incorporates the necessary security patches.

3

What systems are affected by CVE-2008-0960?

CVE-2008-0960 affects various versions of Net-SNMP and UCD-SNMP used in systems like Cisco IOS, CatOS, and others.

4

What type of vulnerability is CVE-2008-0960?

CVE-2008-0960 is classified as an authentication bypass vulnerability impacting the integrity of SNMPv3 packets.

5

Can CVE-2008-0960 be exploited remotely?

Yes, CVE-2008-0960 can be exploited remotely if an attacker can send manipulated SNMPv3 packets to the affected systems.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203