Multiple Vendor SNMP World Writeable Community Vulnerability

BID:986

Info

Multiple Vendor SNMP World Writeable Community Vulnerability

Bugtraq ID: 986
Class: Unknown
CVE:
Remote: Yes
Local: No
Published: Feb 15 2000 12:00AM
Updated: Apr 16 2008 12:29AM
Credit: This was posted to Bugtraq by Michal Zalewski on Feb 15, 2000. Alhambra wrote an article about this for issue 50 of Phrack. It is linked to below. Information regarding default communities for Brocade fabric switches was provided by Jonathan Clemens <j
Vulnerable: Xyplex Router 6.1.1
Sun Solaris 2.6
Microsoft Windows NT 4.0
+ Microsoft Windows NT Enterprise Server 4.0
+ Microsoft Windows NT Enterprise Server 4.0
+ Microsoft Windows NT Server 4.0
+ Microsoft Windows NT Server 4.0
+ Microsoft Windows NT Terminal Server 4.0
+ Microsoft Windows NT Terminal Server 4.0
+ Microsoft Windows NT Workstation 4.0
+ Microsoft Windows NT Workstation 4.0
Microsoft Windows 98
Cray MatchBox Router 2.0.1
Cisco IOS 11.2
Brocade Fabric OS 2.1.2
Ascom COLTSOHO 2.0.21
Not Vulnerable: Sun Solaris 7.0
Microsoft Windows NT 4.0 SP4
+ Microsoft Windows NT Enterprise Server 4.0 SP4
+ Microsoft Windows NT Enterprise Server 4.0 SP4
+ Microsoft Windows NT Server 4.0 SP4
+ Microsoft Windows NT Server 4.0 SP4
+ Microsoft Windows NT Terminal Server 4.0 SP4
+ Microsoft Windows NT Terminal Server 4.0 SP4
+ Microsoft Windows NT Workstation 4.0 SP4
+ Microsoft Windows NT Workstation 4.0 SP4

Discussion

Multiple Vendor SNMP World Writeable Community Vulnerability

In a number of network devices/operating systems, some default communites are world-writeable and therefore allow remote users to configure properties of the device/OS without any authorization (other than knowledge of the community name).

Some of the common default communities/vendors are:

public (ascend,cisco,bay networks (nortel),microsoft,sun,3com, aix)
private (cisco,bay networks (nortel),microsoft,3com, brocade, aix, netapp)
write (ascend, very common)
"all private" (sun)
monitor (3com)
manager (3com)
security (3com)
OrigEquipMfr (brocade)
"Secret C0de" (brocade)
admin
default
password
tivoli
openview
community
snmp
snmpd
system (aix, others)
the name of the router (ie, 'gate')

The attacks can include manipulating routing tables and corrupting ARP caches, which can lead to further compromise. This type of vulnerability has been seen for quite some time; more information on it is listed in the credit section.

NOTE: There may be more products shipping with default read/writeable communities. If you have any more information on what may be vulnerable (more specific firmware versions or corrections), email &lt;[email protected]&gt;.

Exploit / POC

Multiple Vendor SNMP World Writeable Community Vulnerability

Michal Zalewski wrote the following exploit example in his post to Bugtraq regarding this issue:

snmpset hostname {private|public} interfaces.ifTable.ifEntry.ifAdminStatus.1 i 2

This will make the primary interface on the target host (with a default community of public or private) change state to two, which is "down".

Solution / Fix

Multiple Vendor SNMP World Writeable Community Vulnerability

Solution:
A permanent fix is to change or remove the default communities. Please see the references for more information.


Sun Solaris 2.6

References

Multiple Vendor SNMP World Writeable Community Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report