CVE Feed

    Dashboard / CVE / CVE-2008-0960

    CVE-2008-0960

    SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.

    Published:Jun 9, 2008
    Last Modified:Apr 23, 2026
    EPS:Jun 10, 2008
    EPSS Score:0.21232
    CVSS Score:10

    Affected Products

    Vendor
    Cisco
    Product
    Ace 10 6504 Bundle With 4 Gbps Throughput
    Vendor
    Cisco
    Product
    Ace 10 6509 Bundle With 8 Gbps Throughput
    Vendor
    Cisco
    Product
    Ace 10 Service Module
    Vendor
    Cisco
    Product
    Ace 20 6504 Bundle With 4gbps Throughput
    Vendor
    Cisco
    Product
    Ace 20 6509 Bundle With 8gbps Throughput
    Vendor
    Cisco
    Product
    Ace 20 Service Module
    Vendor
    Cisco
    Product
    Ace 4710
    Vendor
    Cisco
    Product
    Ace Xml Gateway
    Vendor
    Cisco
    Product
    Catos
    Vendor
    Cisco
    Product
    Cisco Ios
    Vendor
    Cisco
    Product
    Ios
    Vendor
    Cisco
    Product
    Ios Xr
    Vendor
    Cisco
    Product
    Mds 9120
    Vendor
    Cisco
    Product
    Mds 9124
    Vendor
    Cisco
    Product
    Mds 9134
    Vendor
    Cisco
    Product
    Mds 9140
    Vendor
    Cisco
    Product
    Nx Os
    Vendor
    Ecos Sourceware
    Product
    Ecos
    Vendor
    Ingate
    Product
    Ingate Firewall
    Vendor
    Ingate
    Product
    Ingate Siparator
    Vendor
    Juniper
    Product
    Session And Resource Control
    Vendor
    Juniper
    Product
    Src Pe
    Vendor
    Net-snmp
    Product
    Net Snmp
    Vendor
    Redhat
    Product
    Enterprise Linux
    Vendor
    Redhat
    Product
    Rhel Eus
    Vendor
    Sun
    Product
    Solaris
    Vendor
    Sun
    Product
    Sunos

    Common Weakness Enumeration

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High