SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#878044

SNMPv3 improper HMAC validation allows authentication bypass

Overview

A vulnerability in the way implementations of SNMPv3 handle specially crafted packets may allow authentication bypass.

I. Description

SNMP can be configured to utilize version 3, which is the current standard version of SNMP. SNMPv3 incorporates security features such as authentication and privacy control among other features. Authentication for SNMPv3 is done using keyed-Hash Message Authentication Code (HMAC), a message authentication code calculated using a cryptographic hash function in combination with a secret key. Implementations of SNMPv3 may allow a shortened HMAC code in the authenticator field to authenticate to an agent or a trap daemon using a minimum HMAC of 1 byte.

This issue is known to affect Net-SNMP and UCD-SNMP. Other SNMP implementations may also be affected.

II. Impact

This vulnerability allows attackers to read and modify any SNMP object that can be accessed by the impersonated user. Attackers exploiting this vulnerability can view and modify the configuration of these devices.

III. Solution

Upgrade

This vulnerability is addressed in Net-SNMP versions 5.4.1.1, 5.3.2.1, 5.2.4.1, 5.1.4.1, 5.0.11.1 and UCD-SNMP 4.2.7.1. Please see the Net-SNMP download page.

Alternatively, consult your vendor. See the Systems Affected section below for more information.

Apply a patch

Net-SNMP has released a patch to address this issue. For more information refer to SECURITY RELEASE: Multple Net-SNMP Versions Released. Users are encouraged to apply the patch as soon as possible. Note that patch should apply cleanly to UCD-snmp too.

Enable the SNMPv3 privacy subsystem

The configuration should be modified to enable the SNMPv3 privacy subsystem to encrypt the SNMPv3 traffic using a secret, private key. This option does not encrypt the HMAC, but does minimize the possible affects from this vulnerability.

Systems Affected

VendorStatusDate NotifiedDate Updated
3com, Inc.Unknown20-May-2008
ACCESSUnknown2-Jun-2008
AdventNet Inc. Not Vulnerable18-Jun-2008
AlcatelUnknown20-May-2008
Apple Computer, Inc.Unknown2-Jun-2008
Aruba Networks, Inc.Unknown20-May-2008
Asante Technologies, Inc.Unknown13-Jun-2008
Atheros Communications, Inc.Unknown13-Jun-2008
AT&TUnknown20-May-2008
Avaya, Inc.Unknown20-May-2008
Avici Systems, Inc.Unknown20-May-2008
BEA Systems, Inc. Unknown13-Jun-2008
Borderware TechnologiesUnknown20-May-2008
BroUnknown20-May-2008
BroadcomUnknown13-Jun-2008
Charlotte's Web NetworksUnknown20-May-2008
Check Point Software TechnologiesUnknown20-May-2008
Cisco Systems, Inc.Unknown13-Jun-2008
ClavisterUnknown20-May-2008
Computer AssociatesNot Vulnerable20-Jun-2008
Computer Associates eTrust Security ManagementNot Vulnerable20-Jun-2008
Conectiva Inc.Unknown20-May-2008
CosinecomUnknown13-Jun-2008
Covalent TechnologiesUnknown13-Jun-2008
cPanel Inc.Unknown13-Jun-2008
Cray Inc.Unknown20-May-2008
Cyclades, Inc.Unknown13-Jun-2008
D-Link Systems, Inc.Unknown20-May-2008
Data Connection, Ltd.Unknown20-May-2008
Debian GNU/LinuxUnknown20-May-2008
eCosCentricVulnerable13-Jun-2008
EMC CorporationUnknown20-May-2008
Engarde Secure LinuxUnknown20-May-2008
Enterasys NetworksUnknown20-May-2008
EricssonUnknown20-May-2008
eSoft, Inc.Unknown20-May-2008
Extreme NetworksNot Vulnerable17-Jun-2008
F5 Networks, Inc.Unknown20-May-2008
Fedora ProjectUnknown20-May-2008
Force10 Networks, Inc.Not Vulnerable12-Jun-2008
Fortinet, Inc.Not Vulnerable27-May-2008
Foundry Networks, Inc.Not Vulnerable17-Jun-2008
FreeBSD, Inc.Unknown20-May-2008
FujitsuUnknown20-May-2008
Funkwerk Enterprise Communications Not Vulnerable18-Jun-2008
Gentoo LinuxUnknown4-Jun-2008
Global Technology AssociatesUnknown20-May-2008
Harris CorporationUnknown13-Jun-2008
Hewlett-Packard CompanyUnknown20-May-2008
HitachiUnknown20-May-2008
HyperchipUnknown20-May-2008
IBM CorporationNot Vulnerable18-Jun-2008
IBM Corporation (zseries)Unknown20-May-2008
IBM eServerUnknown20-May-2008
Ingrian Networks, Inc.Unknown20-May-2008
Inktomi Corporation (now Yahoo!)Unknown13-Jun-2008
Intel CorporationNot Vulnerable21-May-2008
Internet Initiative JapanVulnerable19-Jun-2008
Internet Security Systems, Inc.Not Vulnerable4-Jun-2008
IntotoUnknown20-May-2008
IP FilterUnknown20-May-2008
IP Infusion, Inc.Unknown20-May-2008
Juniper Networks, Inc.Vulnerable9-Jun-2008
LantronixUnknown13-Jun-2008
Linux Kernel ArchivesUnknown20-May-2008
Lotus SoftwareUnknown13-Jun-2008
Lucent TechnologiesUnknown20-May-2008
Luminous NetworksUnknown20-May-2008
m0n0wallUnknown20-May-2008
Mandriva, Inc.Unknown20-May-2008
Marconi, Inc.Unknown13-Jun-2008
McAfeeUnknown20-May-2008
MetaSwitchUnknown13-Jun-2008
Metrobility, Inc.Unknown13-Jun-2008
Microsoft CorporationNot Vulnerable28-May-2008
MontaVista Software, Inc.Unknown20-May-2008
Motion Media Technologies, Inc.Unknown13-Jun-2008
Multinet (owned Process Software Corporation)Unknown20-May-2008
Multitech, Inc.Unknown20-May-2008
NEC CorporationUnknown20-May-2008
Net-PolicyUnknown13-Jun-2008
NetBSDUnknown20-May-2008
netfilterUnknown20-May-2008
Netgear, Inc.Unknown13-Jun-2008
Netscape Communications CorporationUnknown13-Jun-2008
netsnmpVulnerable10-Jun-2008
netsnmpjUnknown13-Jun-2008
Network Appliance, Inc.Vulnerable4-Jun-2008
NextHop Technologies, Inc.Unknown20-May-2008
NokiaUnknown20-May-2008
Nortel Networks, Inc.Unknown20-May-2008
Novell, Inc.Not Vulnerable4-Jun-2008
OpenBSDUnknown20-May-2008
openSNMPUnknown13-Jun-2008
Openwall GNU/*/LinuxUnknown20-May-2008
Oracle CorporationUnknown13-Jun-2008
PolycomUnknown13-Jun-2008
QNX, Software Systems, Inc.Unknown20-May-2008
QuaggaUnknown20-May-2008
QUALCOMM IncorporatedUnknown13-Jun-2008
Rad Vision, Inc.Unknown13-Jun-2008
Red Hat, Inc.Vulnerable6-Jun-2008
Redback Networks, Inc.Unknown20-May-2008
Riverstone Networks, Inc.Unknown20-May-2008
Secure Computing Network Security DivisionUnknown20-May-2008
Secureworx, Inc.Unknown20-May-2008
Silicon Graphics, Inc.Unknown20-May-2008
Slackware Linux Inc.Unknown20-May-2008
SmoothWallUnknown20-May-2008
SNMP ResearchVulnerable6-Jun-2008
SnortUnknown20-May-2008
Soapstone NetworksUnknown2-Jun-2008
Sony CorporationUnknown20-May-2008
SourcefireUnknown20-May-2008
StonesoftNot Vulnerable23-Jun-2008
Sun Microsystems, Inc.Vulnerable16-Jun-2008
SUSE LinuxUnknown20-May-2008
Symantec, Inc.Unknown20-May-2008
The SCO GroupUnknown20-May-2008
The Teamware GroupUnknown13-Jun-2008
TippingPoint, Technologies, Inc.Not Vulnerable21-May-2008
Trustix Secure LinuxUnknown20-May-2008
TurbolinuxUnknown20-May-2008
UbuntuUnknown20-May-2008
Vertical Networks, Inc.Unknown13-Jun-2008
Watchguard Technologies, Inc.Unknown20-May-2008
Wind River Systems, Inc.Unknown20-May-2008
ZyXELUnknown20-May-2008

References


http://sourceforge.net/forum/forum.php?forum_id=833770
http://www.ocert.org/advisories/ocert-2008-006.html
http://secunia.com/advisories/30574/
http://secunia.com/advisories/30665/
http://sunsolve.sun.com/search/document.do?assetkey=1-66-238865-1

Credit

This issue was reported by Wes Hardaker at Net-SNMP. Thanks also to Jeff Case of SNMP Research and oCERT.

This document was written by Chris Taschner and David Warren.

Other Information

Date Public:2008-05-31
Date First Published:2008-06-10
Date Last Updated:2008-06-25
CERT Advisory: 
CVE-ID(s):CVE-2008-0960
NVD-ID(s):CVE-2008-0960
US-CERT Technical Alerts:TA08-162A
Metric:7.56
Document Revision:34

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2008 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader