CVE-2008-0960: Critical severity Cisco CatOS vulnerability
CERT has told us of an authentication bypass flaw in Net-SNMP and UCD-SNMP.
According to net-snmp:
"The quick technical summary is that the SNMPv3 packet contains a truncated HMAC authentication code. The author that wrote the code very very long ago to check that HMAC code used the length of the packet's version of the HMAC code to do the check. Thus if you send a single byte HMAC code, it'll only check it against the first byte of HMAC output. Thus it's fairly easy to spoof an authenticated SNMPv3 packet."
Other sources
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0960?
The CVE-2008-0960 vulnerability is considered critical due to its potential for authentication bypass.
How do I fix CVE-2008-0960?
To fix CVE-2008-0960, upgrade to the latest version of Net-SNMP or UCD-SNMP that incorporates the necessary security patches.
What systems are affected by CVE-2008-0960?
CVE-2008-0960 affects various versions of Net-SNMP and UCD-SNMP used in systems like Cisco IOS, CatOS, and others.
What type of vulnerability is CVE-2008-0960?
CVE-2008-0960 is classified as an authentication bypass vulnerability impacting the integrity of SNMPv3 packets.
Can CVE-2008-0960 be exploited remotely?
Yes, CVE-2008-0960 can be exploited remotely if an attacker can send manipulated SNMPv3 packets to the affected systems.