Castle Rock Computing SNMPc v5/v6 Unauthorized Remote Privileged Access Vulnerability

BID:8484

Info

Castle Rock Computing SNMPc v5/v6 Unauthorized Remote Privileged Access Vulnerability

Bugtraq ID: 8484
Class: Design Error
CVE: CVE-2003-0745
Remote: Yes
Local: No
Published: Aug 25 2003 12:00AM
Updated: Mar 19 2015 09:34AM
Credit: The discovery of this vulnerability has been credited to "Alexander V. Nickolenko" <[email protected]>.
Vulnerable: Castlerock SNMPc 6.0.8
Castlerock SNMPc 6.0.5
Castlerock SNMPc 6.0
Castlerock SNMPc 5.1
Not Vulnerable: Castlerock SNMPc 5.1.9

Discussion

Castle Rock Computing SNMPc v5/v6 Unauthorized Remote Privileged Access Vulnerability

A vulnerability in the authentication mechanism used by SNMPc has been discovered, potentially allowing for unauthorized remote access. The problem lies in the design of the mechanism, specifically the fact that all authentication routines are carried out within the client program. As such, an attacker may be capable of influencing the results of authentication by modifying a client program or reversing the encrypted password transmitted by the server.

The exploitation of this issue could ultimately allow for an attacker to gain unauthorized remote console access as the Administrator user, who by default has Supervisor privileges on affected servers.

This vulnerability affects SNMPc v5 and version v6.

Exploit / POC

Castle Rock Computing SNMPc v5/v6 Unauthorized Remote Privileged Access Vulnerability

A proof of console exploit script has been made available "Alexander V. Nickolenko" &lt;[email protected]&gt;. A sample usage of this exploit is available in the attached message reference.

Solution / Fix

Castle Rock Computing SNMPc v5/v6 Unauthorized Remote Privileged Access Vulnerability

Solution:
Castle Rock Computing has created fixes to address this issue in specific 6.x releases, as well as a completely revised 5.x release which addresses this vulnerability. Users are advised to upgrade as soon as possible.

Fixes:


Castlerock SNMPc 5.1

Castlerock SNMPc 6.0.5

Castlerock SNMPc 6.0.8

References

Castle Rock Computing SNMPc v5/v6 Unauthorized Remote Privileged Access Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report