Vulnerability Details CVE-2008-0960
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.366
EPSS Ranking 96.9%
CVSS Severity
CVSS v2 Score 10.0
Products affected by CVE-2008-0960
-
cpe:2.3:a:juniper:session_and_resource_control:1.0
-
cpe:2.3:a:juniper:session_and_resource_control:2.0
-
cpe:2.3:a:juniper:src_pe:1.0
-
cpe:2.3:a:juniper:src_pe:2.0
-
cpe:2.3:h:cisco:ace_10_6504_bundle_with_4_gbps_throughput:*
-
cpe:2.3:h:cisco:ace_10_6509_bundle_with_8_gbps_throughput:*
-
cpe:2.3:h:cisco:ace_10_service_module:*
-
cpe:2.3:h:cisco:ace_20_6504_bundle_with__4gbps_throughput:*
-
cpe:2.3:h:cisco:ace_20_6509_bundle_with_8gbps_throughput:*
-
cpe:2.3:h:cisco:ace_20_service_module:*
-
cpe:2.3:h:cisco:ace_4710:*
-
cpe:2.3:h:cisco:ace_xml_gateway:5.2
-
cpe:2.3:h:cisco:ace_xml_gateway:6.0
-
cpe:2.3:h:cisco:mds_9120:*
-
cpe:2.3:h:cisco:mds_9124:*
-
cpe:2.3:h:cisco:mds_9134:-
-
cpe:2.3:h:cisco:mds_9140:-
-
cpe:2.3:h:ingate:ingate_firewall:2.2.0
-
cpe:2.3:h:ingate:ingate_firewall:2.2.1
-
cpe:2.3:h:ingate:ingate_firewall:2.2.2
-
cpe:2.3:h:ingate:ingate_firewall:2.3.0
-
cpe:2.3:h:ingate:ingate_firewall:2.4.0
-
cpe:2.3:h:ingate:ingate_firewall:2.4.1
-
cpe:2.3:h:ingate:ingate_firewall:2.5.0
-
cpe:2.3:h:ingate:ingate_firewall:2.6.0
-
cpe:2.3:h:ingate:ingate_firewall:2.6.1
-
cpe:2.3:h:ingate:ingate_firewall:3.0.2
-
cpe:2.3:h:ingate:ingate_firewall:3.1.0
-
cpe:2.3:h:ingate:ingate_firewall:3.1.1
-
cpe:2.3:h:ingate:ingate_firewall:3.1.3
-
cpe:2.3:h:ingate:ingate_firewall:3.1.4
-
cpe:2.3:h:ingate:ingate_firewall:3.2.0
-
cpe:2.3:h:ingate:ingate_firewall:3.2.1
-
cpe:2.3:h:ingate:ingate_firewall:3.2.2
-
cpe:2.3:h:ingate:ingate_firewall:3.3.1
-
cpe:2.3:h:ingate:ingate_firewall:4.1.0
-
cpe:2.3:h:ingate:ingate_firewall:4.1.3
-
cpe:2.3:h:ingate:ingate_firewall:4.2.1
-
cpe:2.3:h:ingate:ingate_firewall:4.2.2
-
cpe:2.3:h:ingate:ingate_firewall:4.2.3
-
cpe:2.3:h:ingate:ingate_firewall:4.3.1
-
cpe:2.3:h:ingate:ingate_firewall:4.4.1
-
cpe:2.3:h:ingate:ingate_firewall:4.4.2
-
cpe:2.3:h:ingate:ingate_firewall:4.5.1
-
cpe:2.3:h:ingate:ingate_firewall:4.5.2
-
cpe:2.3:h:ingate:ingate_firewall:4.6.0
-
cpe:2.3:h:ingate:ingate_firewall:4.6.1
-
cpe:2.3:h:ingate:ingate_firewall:4.6.2
-
cpe:2.3:h:ingate:ingate_siparator:2.2.0
-
cpe:2.3:h:ingate:ingate_siparator:2.2.1
-
cpe:2.3:h:ingate:ingate_siparator:2.2.2
-
cpe:2.3:h:ingate:ingate_siparator:2.3.0
-
cpe:2.3:h:ingate:ingate_siparator:2.4.0
-
cpe:2.3:h:ingate:ingate_siparator:2.4.1
-
cpe:2.3:h:ingate:ingate_siparator:2.5.0
-
cpe:2.3:h:ingate:ingate_siparator:2.6.0
-
cpe:2.3:h:ingate:ingate_siparator:2.6.1
-
cpe:2.3:h:ingate:ingate_siparator:3.0.2
-
cpe:2.3:h:ingate:ingate_siparator:3.1.0
-
cpe:2.3:h:ingate:ingate_siparator:3.1.1
-
cpe:2.3:h:ingate:ingate_siparator:3.1.3
-
cpe:2.3:h:ingate:ingate_siparator:3.1.4
-
cpe:2.3:h:ingate:ingate_siparator:3.2.0
-
cpe:2.3:h:ingate:ingate_siparator:3.2.1
-
cpe:2.3:h:ingate:ingate_siparator:3.2.2
-
cpe:2.3:h:ingate:ingate_siparator:3.3.1
-
cpe:2.3:h:ingate:ingate_siparator:4.1.0
-
cpe:2.3:h:ingate:ingate_siparator:4.1.3
-
cpe:2.3:h:ingate:ingate_siparator:4.2.1
-
cpe:2.3:h:ingate:ingate_siparator:4.2.2
-
cpe:2.3:h:ingate:ingate_siparator:4.2.3
-
cpe:2.3:h:ingate:ingate_siparator:4.3.1
-
cpe:2.3:h:ingate:ingate_siparator:4.3.4
-
cpe:2.3:h:ingate:ingate_siparator:4.4.1
-
cpe:2.3:h:ingate:ingate_siparator:4.4.2
-
cpe:2.3:h:ingate:ingate_siparator:4.5.1
-
cpe:2.3:h:ingate:ingate_siparator:4.5.2
-
cpe:2.3:h:ingate:ingate_siparator:4.6.0
-
cpe:2.3:h:ingate:ingate_siparator:4.6.1
-
cpe:2.3:h:ingate:ingate_siparator:4.6.2
-
cpe:2.3:o:cisco:catos:7.1.1
-
cpe:2.3:o:cisco:catos:7.3.1
-
cpe:2.3:o:cisco:catos:7.4.1
-
cpe:2.3:o:cisco:catos:8.3
-
cpe:2.3:o:cisco:cisco_ios:12.0
-
cpe:2.3:o:cisco:cisco_ios:12.1
-
cpe:2.3:o:cisco:cisco_ios:12.2
-
cpe:2.3:o:cisco:cisco_ios:12.3
-
cpe:2.3:o:cisco:cisco_ios:12.4
-
-
-
-
-
-
cpe:2.3:o:cisco:ios_xr:2.0
-
cpe:2.3:o:cisco:ios_xr:3.0
-
cpe:2.3:o:cisco:ios_xr:3.2
-
cpe:2.3:o:cisco:ios_xr:3.3
-
cpe:2.3:o:cisco:ios_xr:3.4
-
cpe:2.3:o:cisco:ios_xr:3.5
-
cpe:2.3:o:cisco:ios_xr:3.6
-
cpe:2.3:o:cisco:ios_xr:3.7
-
cpe:2.3:o:cisco:nx_os:4.0
-
cpe:2.3:o:cisco:nx_os:4.0.1
-
cpe:2.3:o:cisco:nx_os:4.0.2
-
cpe:2.3:o:ecos_sourceware:ecos:1.1
-
cpe:2.3:o:ecos_sourceware:ecos:1.2.1
-
cpe:2.3:o:ecos_sourceware:ecos:1.3.1
-
cpe:2.3:o:ecos_sourceware:ecos:2.0
-
cpe:2.3:o:net-snmp:net_snmp:5.0
-
cpe:2.3:o:net-snmp:net_snmp:5.0.1
-
cpe:2.3:o:net-snmp:net_snmp:5.0.2
-
cpe:2.3:o:net-snmp:net_snmp:5.0.3
-
cpe:2.3:o:net-snmp:net_snmp:5.0.4
-
cpe:2.3:o:net-snmp:net_snmp:5.0.5
-
cpe:2.3:o:net-snmp:net_snmp:5.0.6
-
cpe:2.3:o:net-snmp:net_snmp:5.0.7
-
cpe:2.3:o:net-snmp:net_snmp:5.0.8
-
cpe:2.3:o:net-snmp:net_snmp:5.0.9
-
cpe:2.3:o:net-snmp:net_snmp:5.1
-
cpe:2.3:o:net-snmp:net_snmp:5.1.1
-
cpe:2.3:o:net-snmp:net_snmp:5.1.2
-
cpe:2.3:o:net-snmp:net_snmp:5.2
-
cpe:2.3:o:net-snmp:net_snmp:5.3
-
cpe:2.3:o:net-snmp:net_snmp:5.3.0.1
-
cpe:2.3:o:net-snmp:net_snmp:5.4
-
cpe:2.3:o:sun:solaris:10.0
-