CVE-2008-0960

Summary

CVECVE-2008-0960
StatePUBLISHED
Assignercertcc
Source PriorityCVE Program / NVD first with legacy fallback
Published2008-06-10 18:32:00 UTC
Updated2026-04-23 00:35:47 UTC
DescriptionSNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.

Risk And Classification

Primary CVSS: v2.0 10 from [email protected]

AV:N/AC:L/Au:N/C:C/I:C/A:C

Problem Types: CWE-287 | n/a

CVSS v2.0 Breakdown

Access Vector
Network
Access Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete

AV:N/AC:L/Au:N/C:C/I:C/A:C

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Hardware Cisco Ace 10 6504 Bundle With 4 Gbps Throughput All All All All
Hardware Cisco Ace 10 6509 Bundle With 8 Gbps Throughput All All All All
Hardware Cisco Ace 10 Service Module All All All All
Hardware Cisco Ace 20 6504 Bundle With 4gbps Throughput All All All All
Hardware Cisco Ace 20 6509 Bundle With 8gbps Throughput All All All All
Hardware Cisco Ace 20 Service Module All All All All
Hardware Cisco Ace 4710 All All All All
Hardware Cisco Ace Xml Gateway 5.2 All All All
Hardware Cisco Ace Xml Gateway 6.0 All All All
Operating System Cisco Catos 7.1.1 All All All
Operating System Cisco Catos 7.3.1 All All All
Operating System Cisco Catos 7.4.1 All All All
Operating System Cisco Catos 8.3 All All All
Operating System Cisco Cisco Ios 12.0 s All All
Operating System Cisco Cisco Ios 12.0 sy All All
Operating System Cisco Cisco Ios 12.1 e All All
Operating System Cisco Cisco Ios 12.2 ewa All All
Operating System Cisco Cisco Ios 12.2 jk All All
Operating System Cisco Cisco Ios 12.2 sb All All
Operating System Cisco Cisco Ios 12.2 sg All All
Operating System Cisco Cisco Ios 12.2 sga All All
Operating System Cisco Cisco Ios 12.2 sra All All
Operating System Cisco Cisco Ios 12.2 srb All All
Operating System Cisco Cisco Ios 12.2 src All All
Operating System Cisco Cisco Ios 12.2 sxb All All
Operating System Cisco Cisco Ios 12.2 sxd All All
Operating System Cisco Cisco Ios 12.2 sxf All All
Operating System Cisco Cisco Ios 12.2 zl All All
Operating System Cisco Cisco Ios 12.2 zy All All
Operating System Cisco Cisco Ios 12.3 All All All
Operating System Cisco Cisco Ios 12.3 b All All
Operating System Cisco Cisco Ios 12.3 ja All All
Operating System Cisco Cisco Ios 12.3 jeb All All
Operating System Cisco Cisco Ios 12.3 jk All All
Operating System Cisco Cisco Ios 12.3 jl All All
Operating System Cisco Cisco Ios 12.3 jx All All
Operating System Cisco Cisco Ios 12.3 t All All
Operating System Cisco Cisco Ios 12.3 xa All All
Operating System Cisco Cisco Ios 12.3 xg All All
Operating System Cisco Cisco Ios 12.3 xi All All
Operating System Cisco Cisco Ios 12.3 xk All All
Operating System Cisco Cisco Ios 12.3 xr All All
Operating System Cisco Cisco Ios 12.3 yf All All
Operating System Cisco Cisco Ios 12.3 yi All All
Operating System Cisco Cisco Ios 12.3 yt All All
Operating System Cisco Cisco Ios 12.3 yx All All
Operating System Cisco Cisco Ios 12.4 All All All
Operating System Cisco Cisco Ios 12.4 t All All
Operating System Cisco Cisco Ios 12.4 xa All All
Operating System Cisco Cisco Ios 12.4 xc All All
Operating System Cisco Cisco Ios 12.4 xd All All
Operating System Cisco Cisco Ios 12.4 xe All All
Operating System Cisco Cisco Ios 12.4 xj All All
Operating System Cisco Cisco Ios 12.4 xw All All
Operating System Cisco Ios 10.0 All All All
Operating System Cisco Ios 11.0 All All All
Operating System Cisco Ios 11.1 All All All
Operating System Cisco Ios 11.3 All All All
Operating System Cisco Ios 12.2 All All All
Operating System Cisco Ios Xr 2.0 All All All
Operating System Cisco Ios Xr 3.0 All All All
Operating System Cisco Ios Xr 3.2 All All All
Operating System Cisco Ios Xr 3.3 All All All
Operating System Cisco Ios Xr 3.4 All All All
Operating System Cisco Ios Xr 3.5 All All All
Operating System Cisco Ios Xr 3.6 All All All
Operating System Cisco Ios Xr 3.7 All All All
Hardware Cisco Mds 9120 All All All All
Hardware Cisco Mds 9124 All All All All
Hardware Cisco Mds 9134 All All All All
Hardware Cisco Mds 9140 All All All All
Operating System Cisco Nx Os 4.0 All All All
Operating System Cisco Nx Os 4.0.1 a All All
Operating System Cisco Nx Os 4.0.2 All All All
Operating System Ecos Sourceware Ecos 1.1 All All All
Operating System Ecos Sourceware Ecos 1.2.1 All All All
Operating System Ecos Sourceware Ecos 1.3.1 All All All
Operating System Ecos Sourceware Ecos 2.0 All All All
Operating System Ecos Sourceware Ecos 2.0 b1 All All
Hardware Ingate Ingate Firewall 2.2.0 All All All
Hardware Ingate Ingate Firewall 2.2.1 All All All
Hardware Ingate Ingate Firewall 2.2.2 All All All
Hardware Ingate Ingate Firewall 2.3.0 All All All
Hardware Ingate Ingate Firewall 2.4.0 All All All
Hardware Ingate Ingate Firewall 2.4.1 All All All
Hardware Ingate Ingate Firewall 2.5.0 All All All
Hardware Ingate Ingate Firewall 2.6.0 All All All
Hardware Ingate Ingate Firewall 2.6.1 All All All
Hardware Ingate Ingate Firewall 3.0.2 All All All
Hardware Ingate Ingate Firewall 3.1.0 All All All
Hardware Ingate Ingate Firewall 3.1.1 All All All
Hardware Ingate Ingate Firewall 3.1.3 All All All
Hardware Ingate Ingate Firewall 3.1.4 All All All
Hardware Ingate Ingate Firewall 3.2.0 All All All
Hardware Ingate Ingate Firewall 3.2.1 All All All
Hardware Ingate Ingate Firewall 3.2.2 All All All
Hardware Ingate Ingate Firewall 3.3.1 All All All
Hardware Ingate Ingate Firewall 4.1.0 All All All
Hardware Ingate Ingate Firewall 4.1.3 All All All
Hardware Ingate Ingate Firewall 4.2.1 All All All
Hardware Ingate Ingate Firewall 4.2.2 All All All
Hardware Ingate Ingate Firewall 4.2.3 All All All
Hardware Ingate Ingate Firewall 4.3.1 All All All
Hardware Ingate Ingate Firewall 4.4.1 All All All
Hardware Ingate Ingate Firewall 4.4.2 All All All
Hardware Ingate Ingate Firewall 4.5.1 All All All
Hardware Ingate Ingate Firewall 4.5.2 All All All
Hardware Ingate Ingate Firewall 4.6.0 All All All
Hardware Ingate Ingate Firewall 4.6.1 All All All
Hardware Ingate Ingate Firewall 4.6.2 All All All
Hardware Ingate Ingate Siparator 2.2.0 All All All
Hardware Ingate Ingate Siparator 2.2.1 All All All
Hardware Ingate Ingate Siparator 2.2.2 All All All
Hardware Ingate Ingate Siparator 2.3.0 All All All
Hardware Ingate Ingate Siparator 2.4.0 All All All
Hardware Ingate Ingate Siparator 2.4.1 All All All
Hardware Ingate Ingate Siparator 2.5.0 All All All
Hardware Ingate Ingate Siparator 2.6.0 All All All
Hardware Ingate Ingate Siparator 2.6.1 All All All
Hardware Ingate Ingate Siparator 3.0.2 All All All
Hardware Ingate Ingate Siparator 3.1.0 All All All
Hardware Ingate Ingate Siparator 3.1.1 All All All
Hardware Ingate Ingate Siparator 3.1.3 All All All
Hardware Ingate Ingate Siparator 3.1.4 All All All
Hardware Ingate Ingate Siparator 3.2.0 All All All
Hardware Ingate Ingate Siparator 3.2.1 All All All
Hardware Ingate Ingate Siparator 3.2.2 All All All
Hardware Ingate Ingate Siparator 3.3.1 All All All
Hardware Ingate Ingate Siparator 4.1.0 All All All
Hardware Ingate Ingate Siparator 4.1.3 All All All
Hardware Ingate Ingate Siparator 4.2.1 All All All
Hardware Ingate Ingate Siparator 4.2.2 All All All
Hardware Ingate Ingate Siparator 4.2.3 All All All
Hardware Ingate Ingate Siparator 4.3.1 All All All
Hardware Ingate Ingate Siparator 4.3.4 All All All
Hardware Ingate Ingate Siparator 4.4.1 All All All
Hardware Ingate Ingate Siparator 4.4.2 All All All
Hardware Ingate Ingate Siparator 4.5.1 All All All
Hardware Ingate Ingate Siparator 4.5.2 All All All
Hardware Ingate Ingate Siparator 4.6.0 All All All
Hardware Ingate Ingate Siparator 4.6.1 All All All
Hardware Ingate Ingate Siparator 4.6.2 All All All
Application Juniper Session And Resource Control 1.0 All All All
Application Juniper Session And Resource Control 2.0 All All All
Application Juniper Src Pe 1.0 All All All
Application Juniper Src Pe 2.0 All All All
Operating System Net-snmp Net Snmp 5.0 All All All
Operating System Net-snmp Net Snmp 5.0.1 All All All
Operating System Net-snmp Net Snmp 5.0.2 All All All
Operating System Net-snmp Net Snmp 5.0.3 All All All
Operating System Net-snmp Net Snmp 5.0.4 All All All
Operating System Net-snmp Net Snmp 5.0.5 All All All
Operating System Net-snmp Net Snmp 5.0.6 All All All
Operating System Net-snmp Net Snmp 5.0.7 All All All
Operating System Net-snmp Net Snmp 5.0.8 All All All
Operating System Net-snmp Net Snmp 5.0.9 All All All
Operating System Net-snmp Net Snmp 5.1 All All All
Operating System Net-snmp Net Snmp 5.1.1 All All All
Operating System Net-snmp Net Snmp 5.1.2 All All All
Operating System Net-snmp Net Snmp 5.2 All All All
Operating System Net-snmp Net Snmp 5.3 All All All
Operating System Net-snmp Net Snmp 5.3.0.1 All All All
Operating System Net-snmp Net Snmp 5.4 All All All
Operating System Sun Solaris 10.0 unkown x86 All
Operating System Sun Sunos 5.10 All All All

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Na N/a affected n/a Not specified

References

ReferenceSourceLinkTags
rhn.redhat.com | Red Hat Support af854a3a-2127-422b-91ae-364da2661108 rhn.redhat.com
Support / Security / Advisories / / MDVSA-2008:118 | Mandriva af854a3a-2127-422b-91ae-364da2661108 www.mandriva.com
Red Hat update for net-snmp - Secunia Advisories - Vulnerability Intelligence - Secunia.com af854a3a-2127-422b-91ae-364da2661108 secunia.com Vendor Advisory
Avaya Products Net-snmp Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com af854a3a-2127-422b-91ae-364da2661108 secunia.com Vendor Advisory
Repository / Oval Repository af854a3a-2127-422b-91ae-364da2661108 oval.cisecurity.org
Cisco - Networking, Cloud, and Cybersecurity Solutions af854a3a-2127-422b-91ae-364da2661108 www.cisco.com Vendor Advisory
USN-685-1: Net-SNMP vulnerabilities | Ubuntu af854a3a-2127-422b-91ae-364da2661108 www.ubuntu.com
SourceForge.net: News: SECURITY RELEASE: Multple Net-SNMP Versions Released af854a3a-2127-422b-91ae-364da2661108 sourceforge.net
About the security content of Security Update 2008-004 and Mac OS X 10.5.4 af854a3a-2127-422b-91ae-364da2661108 support.apple.com
VUPEN Security - Offensive Cyber Security af854a3a-2127-422b-91ae-364da2661108 www.vupen.com
US-CERT Technical Cyber Security Alert TA08-162A -- SNMPv3 Authentication Bypass Vulnerability af854a3a-2127-422b-91ae-364da2661108 www.us-cert.gov US Government Resource
Ubuntu update for net-snmp - Secunia Advisories - Vulnerability Intelligence - Secunia.com af854a3a-2127-422b-91ae-364da2661108 secunia.com Vendor Advisory
Ingate Firewall and SIParator SNMP HMAC Spoofing - Secunia Advisories - Vulnerability Intelligence - Secunia.com af854a3a-2127-422b-91ae-364da2661108 secunia.com Vendor Advisory
Juniper Networks, Inc. Information for VU#878044 af854a3a-2127-422b-91ae-364da2661108 www.kb.cert.org US Government Resource
Ingate Firewall and SIParator affected by SNMPv3 vulnerability af854a3a-2127-422b-91ae-364da2661108 lists.ingate.com
SUSE update for net-snmp - Secunia Advisories - Vulnerability Intelligence - Secunia.com af854a3a-2127-422b-91ae-364da2661108 secunia.com Vendor Advisory
oCERT.org - oCERT Advisories af854a3a-2127-422b-91ae-364da2661108 www.ocert.org
Fedora update for net-snmp - Secunia Advisories - Vulnerability Intelligence - Secunia.com af854a3a-2127-422b-91ae-364da2661108 secunia.com Vendor Advisory
US-CERT Vulnerability Note VU#878044 af854a3a-2127-422b-91ae-364da2661108 www.kb.cert.org US Government Resource
[SECURITY] Fedora 9 Update: net-snmp-5.4.1-18.fc9 af854a3a-2127-422b-91ae-364da2661108 www.redhat.com
[security-announce] SUSE Security Announcement: net-snmp (SUSE-SA:2008:0 af854a3a-2127-422b-91ae-364da2661108 lists.opensuse.org
SourceForge.net: net-snmp: Detail: 1989089 - 5.3.2: Fixes VU#878044 and CVE-2008-0960 af854a3a-2127-422b-91ae-364da2661108 sourceforge.net
SecurityReason - multiple SNMP implementations HMAC authenticationspoofing af854a3a-2127-422b-91ae-364da2661108 securityreason.com
VUPEN Security - Offensive Cyber Security af854a3a-2127-422b-91ae-364da2661108 www.vupen.com
Cisco Products SNMPv3 Two Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com af854a3a-2127-422b-91ae-364da2661108 secunia.com
VUPEN Security - Offensive Cyber Security af854a3a-2127-422b-91ae-364da2661108 www.vupen.com
VUPEN Security - Offensive Cyber Security af854a3a-2127-422b-91ae-364da2661108 www.vupen.com
[SECURITY] Fedora 7 Update: net-snmp-5.4-18.fc7 af854a3a-2127-422b-91ae-364da2661108 www.redhat.com
VUPEN Security - Offensive Cyber Security af854a3a-2127-422b-91ae-364da2661108 www.vupen.com
Red Hat update for ucd-snmp - Secunia Advisories - Vulnerability Intelligence - Secunia.com af854a3a-2127-422b-91ae-364da2661108 secunia.com Vendor Advisory
Net-SNMP Remote Authentication Bypass Vulnerability af854a3a-2127-422b-91ae-364da2661108 www.securityfocus.com Exploit, Patch
SecurityFocus af854a3a-2127-422b-91ae-364da2661108 www.securityfocus.com
Network Appliance, Inc. Information for VU#878044 af854a3a-2127-422b-91ae-364da2661108 www.kb.cert.org US Government Resource
SNMP Research Information for VU#878044 af854a3a-2127-422b-91ae-364da2661108 www.kb.cert.org US Government Resource
Repository / Oval Repository af854a3a-2127-422b-91ae-364da2661108 oval.cisecurity.org
VUPEN Security - Offensive Cyber Security af854a3a-2127-422b-91ae-364da2661108 www.vupen.com
[SECURITY] Fedora 8 Update: net-snmp-5.4.1-7.fc8 af854a3a-2127-422b-91ae-364da2661108 www.redhat.com
SNMPv3 HMAC validation error Remote Authentication Bypass Exploit af854a3a-2127-422b-91ae-364da2661108 www.exploit-db.com
APPLE-SA-2008-06-30 Security Update 2008-004 and Mac OS X v10.5.4 af854a3a-2127-422b-91ae-364da2661108 lists.apple.com
HP OpenView SNMP Emanate Master Agent HMAC Authentication Spoofing - Secunia Advisories - Vulnerability Information - Secunia.com af854a3a-2127-422b-91ae-364da2661108 secunia.com
Bug 447974 – CVE-2008-0960 net-snmp SNMPv3 authentication bypass (VU#877044) af854a3a-2127-422b-91ae-364da2661108 bugzilla.redhat.com
Repository / Oval Repository af854a3a-2127-422b-91ae-364da2661108 oval.cisecurity.org
Juniper Networks Session and Resource Control Appliances SNMP HMAC Spoofing - Secunia Advisories - Vulnerability Intelligence - Secunia.com af854a3a-2127-422b-91ae-364da2661108 secunia.com Vendor Advisory
VMware updates for OpenSSL, net-snmp, and perl - Secunia Advisories - Vulnerability Intelligence - Secunia.com af854a3a-2127-422b-91ae-364da2661108 secunia.com Vendor Advisory
Apple Mac OS X Security Update Fixes Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com af854a3a-2127-422b-91ae-364da2661108 secunia.com Vendor Advisory
Gentoo update for net-snmp - Secunia Advisories - Vulnerability Intelligence - Secunia.com af854a3a-2127-422b-91ae-364da2661108 secunia.com Vendor Advisory
Net-snmp SNMPv3 Authentication Bug Lets Remote Users Bypass Authentication - SecurityTracker af854a3a-2127-422b-91ae-364da2661108 www.securitytracker.com
VUPEN Security - Offensive Cyber Security af854a3a-2127-422b-91ae-364da2661108 www.vupen.com
VUPEN Security - Offensive Cyber Security af854a3a-2127-422b-91ae-364da2661108 www.vupen.com
VUPEN Security - Offensive Cyber Security af854a3a-2127-422b-91ae-364da2661108 www.vupen.com
VMSA-2008-0017.2 - VMware af854a3a-2127-422b-91ae-364da2661108 www.vmware.com
Security Advisory SA32664 - Debian update for net-snmp - Secunia af854a3a-2127-422b-91ae-364da2661108 secunia.com Vendor Advisory
SecurityFocus af854a3a-2127-422b-91ae-364da2661108 www.securityfocus.com
Webmail : Solution de messagerie professionnelle - OVHcloud- OVH af854a3a-2127-422b-91ae-364da2661108 www.vupen.com
Support | Red Hat af854a3a-2127-422b-91ae-364da2661108 www.redhat.com
Sun Solaris SNMPv3 Authentication Bypass - Secunia Advisories - Vulnerability Intelligence - Secunia.com af854a3a-2127-422b-91ae-364da2661108 secunia.com Vendor Advisory
Net-SNMP HMAC Authentication Spoofing Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com af854a3a-2127-422b-91ae-364da2661108 secunia.com Vendor Advisory
VMSA-2008-0013.3 - VMware af854a3a-2127-422b-91ae-364da2661108 www.vmware.com
'[security bulletin] HPSBMA02439 SSRT080082 rev.2 - HP OpenView SNMP Emanate Master Agent Running on' - MARC af854a3a-2127-422b-91ae-364da2661108 marc.info
Debian -- Security Information -- DSA-1663-1 net-snmp af854a3a-2127-422b-91ae-364da2661108 www.debian.org Patch
oss-security - [oCERT-2008-006] multiple SNMP implementations HMAC authentication spoofing af854a3a-2127-422b-91ae-364da2661108 www.openwall.com
Net-SNMP: Multiple vulnerabilities — Gentoo Linux Documentation af854a3a-2127-422b-91ae-364da2661108 security.gentoo.org
ASA-2008-282 (RHSA-2008-0529) af854a3a-2127-422b-91ae-364da2661108 support.avaya.com
sunsolve.sun.com/search/document.do af854a3a-2127-422b-91ae-364da2661108 sunsolve.sun.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report