Vulnerability Note VU#878044
SNMPv3 improper HMAC validation allows authentication bypass
Overview
A vulnerability in the way implementations of SNMPv3 handle specially crafted packets may allow authentication bypass.
Description
SNMP can be configured to utilize version 3, which is the current standard version of SNMP. SNMPv3 incorporates security features such as authentication and privacy control among other features. Authentication for SNMPv3 is done using keyed-Hash Message Authentication Code (HMAC), a message authentication code calculated using a cryptographic hash function in combination with a secret key. Implementations of SNMPv3 may allow a shortened HMAC code in the authenticator field to authenticate to an agent or a trap daemon using a minimum HMAC of 1 byte. This issue is known to affect Net-SNMP and UCD-SNMP. Other SNMP implementations may also be affected. |
Impact
This vulnerability allows attackers to read and modify any SNMP object that can be accessed by the impersonated user. Attackers exploiting this vulnerability can view and modify the configuration of these devices. |
Solution
|
|
Systems Affected
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| 3com, Inc. | Unknown | 20 May 2008 | 16 Jul 2009 |
| ACCESS | Unknown | 02 Jun 2008 | 16 Jul 2009 |
| AdventNet Inc. | Not Vulnerable | 13 Jun 2008 | 16 Jul 2009 |
| Alcatel | Unknown | 20 May 2008 | 16 Jul 2009 |
| Apple Computer, Inc. | Unknown | 02 Jun 2008 | 16 Jul 2009 |
| Aruba Networks, Inc. | Unknown | 20 May 2008 | 16 Jul 2009 |
| Asante Technologies, Inc. | Unknown | 13 Jun 2008 | 16 Jul 2009 |
| Atheros Communications, Inc. | Unknown | 13 Jun 2008 | 16 Jul 2009 |
| AT&T | Unknown | 20 May 2008 | 16 Jul 2009 |
| Avaya, Inc. | Unknown | 20 May 2008 | 16 Jul 2009 |
| Avici Systems, Inc. | Unknown | 20 May 2008 | 16 Jul 2009 |
| BEA Systems, Inc. | Unknown | 13 Jun 2008 | 16 Jul 2009 |
| Borderware Technologies | Unknown | 20 May 2008 | 16 Jul 2009 |
| Bro | Unknown | 20 May 2008 | 16 Jul 2009 |
| Broadcom | Unknown | 13 Jun 2008 | 16 Jul 2009 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://sourceforge.net/forum/forum.php?forum_id=833770
- http://www.ocert.org/advisories/ocert-2008-006.html
- http://secunia.com/advisories/30574/
- http://secunia.com/advisories/30665/
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-238865-1
Credit
This issue was reported by Wes Hardaker at Net-SNMP. Thanks also to Jeff Case of SNMP Research and oCERT.
This document was written by Chris Taschner and David Warren.
Other Information
- CVE IDs: CVE-2008-0960
- US-CERT Alert: TA08-162A
- Date Public: 31 May 2008
- Date First Published: 10 Jun 2008
- Date Last Updated: 16 Jul 2009
- Severity Metric: 7.56
- Document Revision: 36
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.
This product is provided subject to the Notification as indicated here: http://www.us-cert.gov/legal.html#notify