Vulnerability Note VU#878044

SNMPv3 improper HMAC validation allows authentication bypass

Original Release date: 10 Jun 2008 | Last revised: 16 Jul 2009

Overview

A vulnerability in the way implementations of SNMPv3 handle specially crafted packets may allow authentication bypass.

Description

SNMP can be configured to utilize version 3, which is the current standard version of SNMP. SNMPv3 incorporates security features such as authentication and privacy control among other features. Authentication for SNMPv3 is done using keyed-Hash Message Authentication Code (HMAC), a message authentication code calculated using a cryptographic hash function in combination with a secret key. Implementations of SNMPv3 may allow a shortened HMAC code in the authenticator field to authenticate to an agent or a trap daemon using a minimum HMAC of 1 byte.

This issue is known to affect Net-SNMP and UCD-SNMP. Other SNMP implementations may also be affected.

Impact

This vulnerability allows attackers to read and modify any SNMP object that can be accessed by the impersonated user. Attackers exploiting this vulnerability can view and modify the configuration of these devices.

Solution


Upgrade

This vulnerability is addressed in Net-SNMP versions 5.4.1.1, 5.3.2.1, 5.2.4.1, 5.1.4.1, 5.0.11.1 and UCD-SNMP 4.2.7.1. Please see the Net-SNMP download page.

Alternatively, consult your vendor. See the Systems Affected section below for more information.

Apply a patch

Net-SNMP has released a patch to address this issue. For more information refer to SECURITY RELEASE: Multple Net-SNMP Versions Released. Users are encouraged to apply the patch as soon as possible. Note that patch should apply cleanly to UCD-snmp too.


Enable the SNMPv3 privacy subsystem

The configuration should be modified to enable the SNMPv3 privacy subsystem to encrypt the SNMPv3 traffic using a secret, private key. This option does not encrypt the HMAC, but does minimize the possible affects from this vulnerability.

Systems Affected

VendorStatusDate NotifiedDate Updated
3com, Inc.Unknown20 May 200816 Jul 2009
ACCESSUnknown02 Jun 200816 Jul 2009
AdventNet Inc. Not Vulnerable13 Jun 200816 Jul 2009
AlcatelUnknown20 May 200816 Jul 2009
Apple Computer, Inc.Unknown02 Jun 200816 Jul 2009
Aruba Networks, Inc.Unknown20 May 200816 Jul 2009
Asante Technologies, Inc.Unknown13 Jun 200816 Jul 2009
Atheros Communications, Inc.Unknown13 Jun 200816 Jul 2009
AT&TUnknown20 May 200816 Jul 2009
Avaya, Inc.Unknown20 May 200816 Jul 2009
Avici Systems, Inc.Unknown20 May 200816 Jul 2009
BEA Systems, Inc. Unknown13 Jun 200816 Jul 2009
Borderware TechnologiesUnknown20 May 200816 Jul 2009
BroUnknown20 May 200816 Jul 2009
BroadcomUnknown13 Jun 200816 Jul 2009
View More »

CVSS Metrics (Learn More)

Group Score Vector
Base N/A N/A
Temporal N/A N/A
Environmental N/A N/A

References

Credit

This issue was reported by Wes Hardaker at Net-SNMP. Thanks also to Jeff Case of SNMP Research and oCERT.

This document was written by Chris Taschner and David Warren.

Other Information

  • CVE IDs: CVE-2008-0960
  • US-CERT Alert: TA08-162A
  • Date Public: 31 May 2008
  • Date First Published: 10 Jun 2008
  • Date Last Updated: 16 Jul 2009
  • Severity Metric: 7.56
  • Document Revision: 36

Feedback

If you have feedback, comments, or additional information about this vulnerability, please send us email.

This product is provided subject to the Notification as indicated here: http://www.us-cert.gov/legal.html#notify

Document Feedback

Was this document helpful?   Yes   |   Somewhat   |  No