net-snmp SNMPv3 authentication bypass (VU#877044)
Published Jun 10, 2008
10.0
HIGHCVSS 2.0
EPSS 68.79%
Description
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.
Affected products
No data.
Running on/with
- 7.1.1
- 7.3.1
- 7.4.1
- 8.3
- 12.0
- 12.0
- 12.1
- 12.2
- 12.2
- 12.2
- 12.2
- 12.2
- 12.2
- 12.2
- 12.2
- 12.2
- 12.2
- 12.2
- 12.2
- 12.2
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.3
- 12.4
- 12.4
- 12.4
- 12.4
- 12.4
- 12.4
- 12.4
- 12.4
- 10.0
- 11.0
- 11.1
- 11.3
- 12.2
- 2.0
- 3.0
- 3.2
- 3.3
- 3.4
- 3.5
- 3.6
- 3.7
- 4.0
- 4.0.1
- 4.0.2
- 1.1
- 1.2.1
- 1.3.1
- 2.0
- 2.0
- 5.0
- 5.0.1
- 5.0.2
- 5.0.3
- 5.0.4
- 5.0.5
- 5.0.6
- 5.0.7
- 5.0.8
- 5.0.9
- 5.1
- 5.1.1
- 5.1.2
- 5.2
- 5.3
- 5.3.0.1
- 5.4
- 10.0
- 5.10
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- 5.2
- 6.0
- n/a
- n/a
- n/a
- n/a
- 2.2.0
- 2.2.1
- 2.2.2
- 2.3.0
- 2.4.0
- 2.4.1
- 2.5.0
- 2.6.0
- 2.6.1
- 3.0.2
- 3.1.0
- 3.1.1
- 3.1.3
- 3.1.4
- 3.2.0
- 3.2.1
- 3.2.2
- 3.3.1
- 4.1.0
- 4.1.3
- 4.2.1
- 4.2.2
- 4.2.3
- 4.3.1
- 4.4.1
- 4.4.2
- 4.5.1
- 4.5.2
- 4.6.0
- 4.6.1
- 4.6.2
- 2.2.0
- 2.2.1
- 2.2.2
- 2.3.0
- 2.4.0
- 2.4.1
- 2.5.0
- 2.6.0
- 2.6.1
- 3.0.2
- 3.1.0
- 3.1.1
- 3.1.3
- 3.1.4
- 3.2.0
- 3.2.1
- 3.2.2
- 3.3.1
- 4.1.0
- 4.1.3
- 4.2.1
- 4.2.2
- 4.2.3
- 4.3.1
- 4.3.4
- 4.4.1
- 4.4.2
- 4.5.1
- 4.5.2
- 4.6.0
- 4.6.1
- 4.6.2
- 1.0
- 2.0
- 1.0
- 2.0
No data.
Red Hat Enterprise Linux 2.1
ucd-snmp-0:4.2.5-8.AS21.7
Fixed · RHSA-2008:0528
Red Hat Enterprise Linux 3
net-snmp-0:5.0.9-2.30E.24
Fixed · RHSA-2008:0529
Red Hat Enterprise Linux 4
net-snmp-0:5.1.2-11.el4_6.11.3
Fixed · RHSA-2008:0529
Red Hat Enterprise Linux 4.5 Z Stream
net-snmp-0:5.1.2-11.el4_6.11.3
Fixed · RHSA-2008:0529
Red Hat Enterprise Linux 5
net-snmp-1:5.3.1-24.el5_2.1
Fixed · RHSA-2008:0529
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 2.1 | ucd-snmp-0:4.2.5-8.AS21.7 | Fixed | RHSA-2008:0528 |
| Red Hat Enterprise Linux 3 | net-snmp-0:5.0.9-2.30E.24 | Fixed | RHSA-2008:0529 |
| Red Hat Enterprise Linux 4 | net-snmp-0:5.1.2-11.el4_6.11.3 | Fixed | RHSA-2008:0529 |
| Red Hat Enterprise Linux 4.5 Z Stream | net-snmp-0:5.1.2-11.el4_6.11.3 | Fixed | RHSA-2008:0529 |
| Red Hat Enterprise Linux 5 | net-snmp-1:5.3.1-24.el5_2.1 | Fixed | RHSA-2008:0529 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (25 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 68.79% (0.68790) | 99.33th | v5 (v2026.06.15) |
| Jun 15, 2026 | 68.79% (0.68790) | 99.25th | v5 (v2026.06.15) |
| May 26, 2026 | 23.49% (0.23493) | 96.05th | v4 (v2025.03.14) |
| Jan 18, 2026 | 21.53% (0.21526) | 95.54th | v4 (v2025.03.14) |
| Dec 6, 2025 | 33.19% (0.33188) | 96.72th | v4 (v2025.03.14) |
| Apr 26, 2025 | 36.63% (0.36632) | 96.88th | v4 (v2025.03.14) |
| Mar 30, 2025 | 56.99% (0.56988) | 97.94th | v4 (v2025.03.14) |
| Mar 29, 2025 | 51.99% (0.51993) | 96.95th | v4 (v2025.03.14) |
| Mar 26, 2025 | 56.99% (0.56988) | 97.93th | v4 (v2025.03.14) |
| Mar 17, 2025 | 49.65% (0.49645) | 97.53th | v4 (v2025.03.14) |
| Mar 7, 2025 | 95.74% (0.95740) | 99.60th | v3 (v2023.03.01) |
| Dec 12, 2024 | 97.00% (0.97004) | 99.80th | v3 (v2023.03.01) |
| May 11, 2024 | 97.06% (0.97056) | 99.76th | v3 (v2023.03.01) |
| Apr 6, 2024 | 97.12% (0.97117) | 99.77th | v3 (v2023.03.01) |
| Mar 1, 2024 | 96.82% (0.96822) | 99.66th | v3 (v2023.03.01) |
| Jan 25, 2024 | 96.95% (0.96955) | 99.68th | v3 (v2023.03.01) |
| Dec 20, 2023 | 96.82% (0.96819) | 99.61th | v3 (v2023.03.01) |
| Nov 14, 2023 | 96.86% (0.96856) | 99.61th | v3 (v2023.03.01) |
| Oct 8, 2023 | 97.16% (0.97162) | 99.73th | v3 (v2023.03.01) |
| Sep 4, 2023 | 97.13% (0.97127) | 99.69th | v3 (v2023.03.01) |
| Apr 10, 2023 | 97.24% (0.97236) | 99.69th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.30% (0.97305) | 99.73th | v3 (v2023.03.01) |
| Mar 6, 2023 | 15.27% (0.15272) | 95.95th | v2 (v2022.01.01) |
| Apr 1, 2022 | 15.27% (0.15272) | 95.58th | v2 (v2022.01.01) |
| Feb 4, 2022 | 15.27% (0.15272) | 91.38th | v2 (v2022.01.01) |
References (67)
- http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html vendor-advisoryx_refsource_APPLE
- http://lists.ingate.com/pipermail/productinfo/2008/000021.html mailing-listx_refsource_MLIST
- http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00000.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=127730470825399&w=2 vendor-advisoryx_refsource_HP
- http://rhn.redhat.com/errata/RHSA-2008-0528.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/30574 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/30596 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/30612 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30615 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/30626 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/30647 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/30648 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/30665 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/30802 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/31334 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/31351 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/31467 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/31568 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/32664 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/33003 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35463 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200808-02.xml vendor-advisoryx_refsource_GENTOO
- http://securityreason.com/securityalert/3933 third-party-advisoryx_refsource_SREASON
- http://sourceforge.net/forum/forum.php?forum_id=833770 x_refsource_CONFIRM
- http://sourceforge.net/tracker/index.php?func=detail&aid=1989089&group_id=12694&atid=456380 x_refsource_CONFIRM
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-238865-1 vendor-advisoryx_refsource_SUNALERT
- http://support.apple.com/kb/HT2163 x_refsource_CONFIRM
- http://support.avaya.com/elmodocs2/security/ASA-2008-282.htm x_refsource_CONFIRM
- http://www.cisco.com/warp/public/707/cisco-sa-20080610-snmpv3.shtml vendor-advisoryx_refsource_CISCOVendor Advisory
- http://www.debian.org/security/2008/dsa-1663 vendor-advisoryx_refsource_DEBIANPatch
- http://www.kb.cert.org/vuls/id/878044 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.kb.cert.org/vuls/id/CTAR-7FBS8Q x_refsource_CONFIRMUS Government Resource
- http://www.kb.cert.org/vuls/id/MIMG-7ETS5Z x_refsource_CONFIRMUS Government Resource
- http://www.kb.cert.org/vuls/id/MIMG-7ETS87 x_refsource_CONFIRMUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:118 vendor-advisoryx_refsource_MANDRIVA
- http://www.ocert.org/advisories/ocert-2008-006.html x_refsource_MISC
- http://www.openwall.com/lists/oss-security/2008/06/09/1 mailing-listx_refsource_MLIST
- http://www.redhat.com/support/errata/RHSA-2008-0529.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/archive/1/493218/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/497962/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/29623 vdb-entryx_refsource_BIDExploitPatch
- http://www.securitytracker.com/id?1020218 vdb-entryx_refsource_SECTRACK
- http://www.ubuntu.com/usn/usn-685-1 vendor-advisoryx_refsource_UBUNTU
- http://www.us-cert.gov/cas/techalerts/TA08-162A.html third-party-advisoryx_refsource_CERTUS Government Resource
- http://www.vmware.com/security/advisories/VMSA-2008-0013.html x_refsource_CONFIRM
- http://www.vmware.com/security/advisories/VMSA-2008-0017.html x_refsource_MISC
- http://www.vupen.com/english/advisories/2008/1787/references vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/1788/references vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/1797/references vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/1800/references vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/1801/references vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/1836/references vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/1981/references vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/2361 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/2971 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2009/1612 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2008-0960 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=447974 x_refsource_CONFIRMIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2008-0960
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10820 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5785 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6414 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2008-0960
- https://www.exploit-db.com/exploits/5790 exploitx_refsource_EXPLOIT-DB
- https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00363.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00380.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00459.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.