CVE-2008-0960 : Detail

CVE-2008-0960

Authorization problems
A07-Identif. and Authent. Fail
95.74%V3
Network
2008-06-10
16h00 +00:00
2018-10-15
18h57 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.

CVE Informations

Related Weaknesses

CWE-ID Weakness Name Source
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Metrics

Metrics Score Severity CVSS Vector Source
V2 10 AV:N/AC:L/Au:N/C:C/I:C/A:C [email protected]

EPSS

EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.

EPSS Score

The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.

EPSS Percentile

The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.

Exploit information

Exploit Database EDB-ID : 5790

Publication date : 2008-06-11 22h00 +00:00
Author : Maurizio Agazzini
EDB Verified : Yes

############################################################################# # # # snmpv3_exp.sh exploit the vulnerability described in CVE-2008-0960, the # # HMAC check problem (on multiple vendor) # # # # Copyright (c) 2008 @ Mediaservice.net Srl. All rights reserved # # Wrote by Maurizio Agazzini <inode[at]mediaservice.net> # # http://lab.mediaservice.net/ # # # ############################################################################# https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/5790.tgz (2008-snmpv3_exp.tgz) # milw0rm.com [2008-06-12]

Products Mentioned

Configuraton 0

Cisco>>Catos >> Version 7.1.1

    Cisco>>Catos >> Version 7.3.1

      Cisco>>Catos >> Version 7.4.1

        Cisco>>Catos >> Version 8.3

        Cisco>>Cisco_ios >> Version 12.0

          Cisco>>Cisco_ios >> Version 12.0

            Cisco>>Cisco_ios >> Version 12.1

              Cisco>>Cisco_ios >> Version 12.2

                Cisco>>Cisco_ios >> Version 12.2

                  Cisco>>Cisco_ios >> Version 12.2

                    Cisco>>Cisco_ios >> Version 12.2

                      Cisco>>Cisco_ios >> Version 12.2

                        Cisco>>Cisco_ios >> Version 12.2

                          Cisco>>Cisco_ios >> Version 12.2

                            Cisco>>Cisco_ios >> Version 12.2

                              Cisco>>Cisco_ios >> Version 12.2

                                Cisco>>Cisco_ios >> Version 12.2

                                  Cisco>>Cisco_ios >> Version 12.2

                                    Cisco>>Cisco_ios >> Version 12.2

                                      Cisco>>Cisco_ios >> Version 12.2

                                        Cisco>>Cisco_ios >> Version 12.3

                                          Cisco>>Cisco_ios >> Version 12.3

                                            Cisco>>Cisco_ios >> Version 12.3

                                              Cisco>>Cisco_ios >> Version 12.3

                                                Cisco>>Cisco_ios >> Version 12.3

                                                  Cisco>>Cisco_ios >> Version 12.3

                                                    Cisco>>Cisco_ios >> Version 12.3

                                                      Cisco>>Cisco_ios >> Version 12.3

                                                        Cisco>>Cisco_ios >> Version 12.3

                                                          Cisco>>Cisco_ios >> Version 12.3

                                                            Cisco>>Cisco_ios >> Version 12.3

                                                              Cisco>>Cisco_ios >> Version 12.3

                                                                Cisco>>Cisco_ios >> Version 12.3

                                                                  Cisco>>Cisco_ios >> Version 12.3

                                                                    Cisco>>Cisco_ios >> Version 12.3

                                                                      Cisco>>Cisco_ios >> Version 12.3

                                                                        Cisco>>Cisco_ios >> Version 12.3

                                                                          Cisco>>Cisco_ios >> Version 12.4

                                                                            Cisco>>Cisco_ios >> Version 12.4

                                                                              Cisco>>Cisco_ios >> Version 12.4

                                                                                Cisco>>Cisco_ios >> Version 12.4

                                                                                  Cisco>>Cisco_ios >> Version 12.4

                                                                                    Cisco>>Cisco_ios >> Version 12.4

                                                                                      Cisco>>Cisco_ios >> Version 12.4

                                                                                        Cisco>>Cisco_ios >> Version 12.4

                                                                                          Cisco>>Ios >> Version 10.0

                                                                                          Cisco>>Ios >> Version 11.0

                                                                                          Cisco>>Ios >> Version 11.1

                                                                                          Cisco>>Ios >> Version 11.3

                                                                                          Cisco>>Ios >> Version 12.2

                                                                                          Cisco>>Ios_xr >> Version 2.0

                                                                                          Cisco>>Ios_xr >> Version 3.0

                                                                                          Cisco>>Ios_xr >> Version 3.2

                                                                                          Cisco>>Ios_xr >> Version 3.3

                                                                                          Cisco>>Ios_xr >> Version 3.4

                                                                                          Cisco>>Ios_xr >> Version 3.5

                                                                                          Cisco>>Ios_xr >> Version 3.6

                                                                                          Cisco>>Ios_xr >> Version 3.7

                                                                                          Cisco>>Nx_os >> Version 4.0

                                                                                            Cisco>>Nx_os >> Version 4.0.1

                                                                                              Cisco>>Nx_os >> Version 4.0.2

                                                                                                Ecos_sourceware>>Ecos >> Version 1.1

                                                                                                  Ecos_sourceware>>Ecos >> Version 1.2.1

                                                                                                    Ecos_sourceware>>Ecos >> Version 1.3.1

                                                                                                      Ecos_sourceware>>Ecos >> Version 2.0

                                                                                                        Ecos_sourceware>>Ecos >> Version 2.0

                                                                                                          Net-snmp>>Net_snmp >> Version 5.0

                                                                                                            Net-snmp>>Net_snmp >> Version 5.0.1

                                                                                                              Net-snmp>>Net_snmp >> Version 5.0.2

                                                                                                                Net-snmp>>Net_snmp >> Version 5.0.3

                                                                                                                  Net-snmp>>Net_snmp >> Version 5.0.4

                                                                                                                    Net-snmp>>Net_snmp >> Version 5.0.5

                                                                                                                      Net-snmp>>Net_snmp >> Version 5.0.6

                                                                                                                        Net-snmp>>Net_snmp >> Version 5.0.7

                                                                                                                          Net-snmp>>Net_snmp >> Version 5.0.8

                                                                                                                            Net-snmp>>Net_snmp >> Version 5.0.9

                                                                                                                              Net-snmp>>Net_snmp >> Version 5.1

                                                                                                                                Net-snmp>>Net_snmp >> Version 5.1.1

                                                                                                                                  Net-snmp>>Net_snmp >> Version 5.1.2

                                                                                                                                    Net-snmp>>Net_snmp >> Version 5.2

                                                                                                                                      Net-snmp>>Net_snmp >> Version 5.3

                                                                                                                                        Net-snmp>>Net_snmp >> Version 5.3.0.1

                                                                                                                                          Net-snmp>>Net_snmp >> Version 5.4

                                                                                                                                            Sun>>Solaris >> Version 10.0

                                                                                                                                              Sun>>Sunos >> Version 5.10

                                                                                                                                              Cisco>>Ace_10_6504_bundle_with_4_gbps_throughput >> Version *

                                                                                                                                                Cisco>>Ace_10_6509_bundle_with_8_gbps_throughput >> Version *

                                                                                                                                                  Cisco>>Ace_10_service_module >> Version *

                                                                                                                                                    Cisco>>Ace_20_6504_bundle_with__4gbps_throughput >> Version *

                                                                                                                                                      Cisco>>Ace_20_6509_bundle_with_8gbps_throughput >> Version *

                                                                                                                                                        Cisco>>Ace_20_service_module >> Version *

                                                                                                                                                          Cisco>>Ace_4710 >> Version *

                                                                                                                                                            Cisco>>Ace_xml_gateway >> Version 5.2

                                                                                                                                                              Cisco>>Ace_xml_gateway >> Version 6.0

                                                                                                                                                                Cisco>>Mds_9120 >> Version *

                                                                                                                                                                  Cisco>>Mds_9124 >> Version *

                                                                                                                                                                    Cisco>>Mds_9134 >> Version *

                                                                                                                                                                    Cisco>>Mds_9140 >> Version *

                                                                                                                                                                    Ingate>>Ingate_firewall >> Version 2.2.0

                                                                                                                                                                      Ingate>>Ingate_firewall >> Version 2.2.1

                                                                                                                                                                        Ingate>>Ingate_firewall >> Version 2.2.2

                                                                                                                                                                          Ingate>>Ingate_firewall >> Version 2.3.0

                                                                                                                                                                            Ingate>>Ingate_firewall >> Version 2.4.0

                                                                                                                                                                              Ingate>>Ingate_firewall >> Version 2.4.1

                                                                                                                                                                                Ingate>>Ingate_firewall >> Version 2.5.0

                                                                                                                                                                                  Ingate>>Ingate_firewall >> Version 2.6.0

                                                                                                                                                                                    Ingate>>Ingate_firewall >> Version 2.6.1

                                                                                                                                                                                      Ingate>>Ingate_firewall >> Version 3.0.2

                                                                                                                                                                                        Ingate>>Ingate_firewall >> Version 3.1.0

                                                                                                                                                                                          Ingate>>Ingate_firewall >> Version 3.1.1

                                                                                                                                                                                            Ingate>>Ingate_firewall >> Version 3.1.3

                                                                                                                                                                                              Ingate>>Ingate_firewall >> Version 3.1.4

                                                                                                                                                                                                Ingate>>Ingate_firewall >> Version 3.2.0

                                                                                                                                                                                                  Ingate>>Ingate_firewall >> Version 3.2.1

                                                                                                                                                                                                    Ingate>>Ingate_firewall >> Version 3.2.2

                                                                                                                                                                                                      Ingate>>Ingate_firewall >> Version 3.3.1

                                                                                                                                                                                                        Ingate>>Ingate_firewall >> Version 4.1.0

                                                                                                                                                                                                          Ingate>>Ingate_firewall >> Version 4.1.3

                                                                                                                                                                                                            Ingate>>Ingate_firewall >> Version 4.2.1

                                                                                                                                                                                                              Ingate>>Ingate_firewall >> Version 4.2.2

                                                                                                                                                                                                                Ingate>>Ingate_firewall >> Version 4.2.3

                                                                                                                                                                                                                  Ingate>>Ingate_firewall >> Version 4.3.1

                                                                                                                                                                                                                    Ingate>>Ingate_firewall >> Version 4.4.1

                                                                                                                                                                                                                      Ingate>>Ingate_firewall >> Version 4.4.2

                                                                                                                                                                                                                        Ingate>>Ingate_firewall >> Version 4.5.1

                                                                                                                                                                                                                          Ingate>>Ingate_firewall >> Version 4.5.2

                                                                                                                                                                                                                            Ingate>>Ingate_firewall >> Version 4.6.0

                                                                                                                                                                                                                              Ingate>>Ingate_firewall >> Version 4.6.1

                                                                                                                                                                                                                                Ingate>>Ingate_firewall >> Version 4.6.2

                                                                                                                                                                                                                                  Ingate>>Ingate_siparator >> Version 2.2.0

                                                                                                                                                                                                                                    Ingate>>Ingate_siparator >> Version 2.2.1

                                                                                                                                                                                                                                      Ingate>>Ingate_siparator >> Version 2.2.2

                                                                                                                                                                                                                                        Ingate>>Ingate_siparator >> Version 2.3.0

                                                                                                                                                                                                                                          Ingate>>Ingate_siparator >> Version 2.4.0

                                                                                                                                                                                                                                            Ingate>>Ingate_siparator >> Version 2.4.1

                                                                                                                                                                                                                                              Ingate>>Ingate_siparator >> Version 2.5.0

                                                                                                                                                                                                                                                Ingate>>Ingate_siparator >> Version 2.6.0

                                                                                                                                                                                                                                                  Ingate>>Ingate_siparator >> Version 2.6.1

                                                                                                                                                                                                                                                    Ingate>>Ingate_siparator >> Version 3.0.2

                                                                                                                                                                                                                                                      Ingate>>Ingate_siparator >> Version 3.1.0

                                                                                                                                                                                                                                                        Ingate>>Ingate_siparator >> Version 3.1.1

                                                                                                                                                                                                                                                          Ingate>>Ingate_siparator >> Version 3.1.3

                                                                                                                                                                                                                                                            Ingate>>Ingate_siparator >> Version 3.1.4

                                                                                                                                                                                                                                                              Ingate>>Ingate_siparator >> Version 3.2.0

                                                                                                                                                                                                                                                                Ingate>>Ingate_siparator >> Version 3.2.1

                                                                                                                                                                                                                                                                  Ingate>>Ingate_siparator >> Version 3.2.2

                                                                                                                                                                                                                                                                    Ingate>>Ingate_siparator >> Version 3.3.1

                                                                                                                                                                                                                                                                      Ingate>>Ingate_siparator >> Version 4.1.0

                                                                                                                                                                                                                                                                        Ingate>>Ingate_siparator >> Version 4.1.3

                                                                                                                                                                                                                                                                          Ingate>>Ingate_siparator >> Version 4.2.1

                                                                                                                                                                                                                                                                            Ingate>>Ingate_siparator >> Version 4.2.2

                                                                                                                                                                                                                                                                              Ingate>>Ingate_siparator >> Version 4.2.3

                                                                                                                                                                                                                                                                                Ingate>>Ingate_siparator >> Version 4.3.1

                                                                                                                                                                                                                                                                                  Ingate>>Ingate_siparator >> Version 4.3.4

                                                                                                                                                                                                                                                                                    Ingate>>Ingate_siparator >> Version 4.4.1

                                                                                                                                                                                                                                                                                      Ingate>>Ingate_siparator >> Version 4.4.2

                                                                                                                                                                                                                                                                                        Ingate>>Ingate_siparator >> Version 4.5.1

                                                                                                                                                                                                                                                                                          Ingate>>Ingate_siparator >> Version 4.5.2

                                                                                                                                                                                                                                                                                            Ingate>>Ingate_siparator >> Version 4.6.0

                                                                                                                                                                                                                                                                                              Ingate>>Ingate_siparator >> Version 4.6.1

                                                                                                                                                                                                                                                                                                Ingate>>Ingate_siparator >> Version 4.6.2

                                                                                                                                                                                                                                                                                                  Juniper>>Session_and_resource_control >> Version 1.0

                                                                                                                                                                                                                                                                                                    Juniper>>Session_and_resource_control >> Version 2.0

                                                                                                                                                                                                                                                                                                      Juniper>>Src_pe >> Version 1.0

                                                                                                                                                                                                                                                                                                        Juniper>>Src_pe >> Version 2.0

                                                                                                                                                                                                                                                                                                          References

                                                                                                                                                                                                                                                                                                          http://secunia.com/advisories/35463
                                                                                                                                                                                                                                                                                                          Tags : third-party-advisory, x_refsource_SECUNIA
                                                                                                                                                                                                                                                                                                          http://secunia.com/advisories/30615
                                                                                                                                                                                                                                                                                                          Tags : third-party-advisory, x_refsource_SECUNIA
                                                                                                                                                                                                                                                                                                          http://support.apple.com/kb/HT2163
                                                                                                                                                                                                                                                                                                          Tags : x_refsource_CONFIRM
                                                                                                                                                                                                                                                                                                          http://secunia.com/advisories/30648
                                                                                                                                                                                                                                                                                                          Tags : third-party-advisory, x_refsource_SECUNIA
                                                                                                                                                                                                                                                                                                          http://secunia.com/advisories/32664
                                                                                                                                                                                                                                                                                                          Tags : third-party-advisory, x_refsource_SECUNIA
                                                                                                                                                                                                                                                                                                          http://secunia.com/advisories/31351
                                                                                                                                                                                                                                                                                                          Tags : third-party-advisory, x_refsource_SECUNIA
                                                                                                                                                                                                                                                                                                          http://www.securityfocus.com/bid/29623
                                                                                                                                                                                                                                                                                                          Tags : vdb-entry, x_refsource_BID
                                                                                                                                                                                                                                                                                                          http://secunia.com/advisories/31334
                                                                                                                                                                                                                                                                                                          Tags : third-party-advisory, x_refsource_SECUNIA
                                                                                                                                                                                                                                                                                                          http://www.vupen.com/english/advisories/2008/2971
                                                                                                                                                                                                                                                                                                          Tags : vdb-entry, x_refsource_VUPEN
                                                                                                                                                                                                                                                                                                          http://secunia.com/advisories/30626
                                                                                                                                                                                                                                                                                                          Tags : third-party-advisory, x_refsource_SECUNIA
                                                                                                                                                                                                                                                                                                          http://marc.info/?l=bugtraq&m=127730470825399&w=2
                                                                                                                                                                                                                                                                                                          Tags : vendor-advisory, x_refsource_HP
                                                                                                                                                                                                                                                                                                          http://www.openwall.com/lists/oss-security/2008/06/09/1
                                                                                                                                                                                                                                                                                                          Tags : mailing-list, x_refsource_MLIST
                                                                                                                                                                                                                                                                                                          http://marc.info/?l=bugtraq&m=127730470825399&w=2
                                                                                                                                                                                                                                                                                                          Tags : vendor-advisory, x_refsource_HP
                                                                                                                                                                                                                                                                                                          http://www.kb.cert.org/vuls/id/878044
                                                                                                                                                                                                                                                                                                          Tags : third-party-advisory, x_refsource_CERT-VN
                                                                                                                                                                                                                                                                                                          http://secunia.com/advisories/30647
                                                                                                                                                                                                                                                                                                          Tags : third-party-advisory, x_refsource_SECUNIA
                                                                                                                                                                                                                                                                                                          http://sunsolve.sun.com/search/document.do?assetkey=1-26-238865-1
                                                                                                                                                                                                                                                                                                          Tags : vendor-advisory, x_refsource_SUNALERT
                                                                                                                                                                                                                                                                                                          http://secunia.com/advisories/33003
                                                                                                                                                                                                                                                                                                          Tags : third-party-advisory, x_refsource_SECUNIA
                                                                                                                                                                                                                                                                                                          http://www.vupen.com/english/advisories/2008/2361
                                                                                                                                                                                                                                                                                                          Tags : vdb-entry, x_refsource_VUPEN
                                                                                                                                                                                                                                                                                                          http://secunia.com/advisories/31568
                                                                                                                                                                                                                                                                                                          Tags : third-party-advisory, x_refsource_SECUNIA
                                                                                                                                                                                                                                                                                                          http://secunia.com/advisories/31467
                                                                                                                                                                                                                                                                                                          Tags : third-party-advisory, x_refsource_SECUNIA
                                                                                                                                                                                                                                                                                                          http://www.debian.org/security/2008/dsa-1663
                                                                                                                                                                                                                                                                                                          Tags : vendor-advisory, x_refsource_DEBIAN
                                                                                                                                                                                                                                                                                                          http://www.us-cert.gov/cas/techalerts/TA08-162A.html
                                                                                                                                                                                                                                                                                                          Tags : third-party-advisory, x_refsource_CERT
                                                                                                                                                                                                                                                                                                          http://rhn.redhat.com/errata/RHSA-2008-0528.html
                                                                                                                                                                                                                                                                                                          Tags : vendor-advisory, x_refsource_REDHAT
                                                                                                                                                                                                                                                                                                          http://securityreason.com/securityalert/3933
                                                                                                                                                                                                                                                                                                          Tags : third-party-advisory, x_refsource_SREASON
                                                                                                                                                                                                                                                                                                          http://www.redhat.com/support/errata/RHSA-2008-0529.html
                                                                                                                                                                                                                                                                                                          Tags : vendor-advisory, x_refsource_REDHAT
                                                                                                                                                                                                                                                                                                          http://secunia.com/advisories/30612
                                                                                                                                                                                                                                                                                                          Tags : third-party-advisory, x_refsource_SECUNIA
                                                                                                                                                                                                                                                                                                          http://secunia.com/advisories/30802
                                                                                                                                                                                                                                                                                                          Tags : third-party-advisory, x_refsource_SECUNIA
                                                                                                                                                                                                                                                                                                          https://www.exploit-db.com/exploits/5790
                                                                                                                                                                                                                                                                                                          Tags : exploit, x_refsource_EXPLOIT-DB
                                                                                                                                                                                                                                                                                                          http://security.gentoo.org/glsa/glsa-200808-02.xml
                                                                                                                                                                                                                                                                                                          Tags : vendor-advisory, x_refsource_GENTOO
                                                                                                                                                                                                                                                                                                          http://secunia.com/advisories/30665
                                                                                                                                                                                                                                                                                                          Tags : third-party-advisory, x_refsource_SECUNIA
                                                                                                                                                                                                                                                                                                          http://www.mandriva.com/security/advisories?name=MDVSA-2008:118
                                                                                                                                                                                                                                                                                                          Tags : vendor-advisory, x_refsource_MANDRIVA
                                                                                                                                                                                                                                                                                                          http://www.ubuntu.com/usn/usn-685-1
                                                                                                                                                                                                                                                                                                          Tags : vendor-advisory, x_refsource_UBUNTU
                                                                                                                                                                                                                                                                                                          http://www.securitytracker.com/id?1020218
                                                                                                                                                                                                                                                                                                          Tags : vdb-entry, x_refsource_SECTRACK
                                                                                                                                                                                                                                                                                                          http://secunia.com/advisories/30596
                                                                                                                                                                                                                                                                                                          Tags : third-party-advisory, x_refsource_SECUNIA
                                                                                                                                                                                                                                                                                                          http://www.vupen.com/english/advisories/2009/1612
                                                                                                                                                                                                                                                                                                          Tags : vdb-entry, x_refsource_VUPEN
                                                                                                                                                                                                                                                                                                          http://secunia.com/advisories/30574
                                                                                                                                                                                                                                                                                                          Tags : third-party-advisory, x_refsource_SECUNIA