CVE-2008-0960
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.
Published:Jun 9, 2008
Last Modified:Apr 23, 2026
EPS:Jun 10, 2008
EPSS Score:0.21232
CVSS Score:10
Affected Products
Vendor
Product
Action
Vendor
Cisco
Product
Ace 10 6504 Bundle With 4 Gbps Throughput
Cisco
Ace 10 6504 Bundle With 4 Gbps Throughput
Vendor
Cisco
Product
Ace 10 6509 Bundle With 8 Gbps Throughput
Cisco
Ace 10 6509 Bundle With 8 Gbps Throughput
Vendor
Cisco
Product
Ace 10 Service Module
Cisco
Ace 10 Service Module
Vendor
Cisco
Product
Ace 20 6504 Bundle With 4gbps Throughput
Cisco
Ace 20 6504 Bundle With 4gbps Throughput
Vendor
Cisco
Product
Ace 20 6509 Bundle With 8gbps Throughput
Cisco
Ace 20 6509 Bundle With 8gbps Throughput
Vendor
Cisco
Product
Ace 20 Service Module
Cisco
Ace 20 Service Module
Vendor
Cisco
Product
Ace 4710
Cisco
Ace 4710
Vendor
Cisco
Product
Ace Xml Gateway
Cisco
Ace Xml Gateway
Vendor
Cisco
Product
Catos
Cisco
Catos
Vendor
Cisco
Product
Cisco Ios
Cisco
Cisco Ios
Vendor
Cisco
Product
Ios
Cisco
Ios
Vendor
Cisco
Product
Ios Xr
Cisco
Ios Xr
Vendor
Cisco
Product
Mds 9120
Cisco
Mds 9120
Vendor
Cisco
Product
Mds 9124
Cisco
Mds 9124
Vendor
Cisco
Product
Mds 9134
Cisco
Mds 9134
Vendor
Cisco
Product
Mds 9140
Cisco
Mds 9140
Vendor
Cisco
Product
Nx Os
Cisco
Nx Os
Vendor
Ecos Sourceware
Product
Ecos
Ecos Sourceware
Ecos
Vendor
Ingate
Product
Ingate Firewall
Ingate
Ingate Firewall
Vendor
Ingate
Product
Ingate Siparator
Ingate
Ingate Siparator
Vendor
Juniper
Product
Session And Resource Control
Juniper
Session And Resource Control
Vendor
Juniper
Product
Src Pe
Juniper
Src Pe
Vendor
Net-snmp
Product
Net Snmp
Net-snmp
Net Snmp
Vendor
Redhat
Product
Enterprise Linux
Redhat
Enterprise Linux
Vendor
Redhat
Product
Rhel Eus
Redhat
Rhel Eus
Vendor
Sun
Product
Solaris
Sun
Solaris
Vendor
Sun
Product
Sunos
Sun
Sunos
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
