← Vulnerability feed

Vulnerability record · CVE-2008-0960 · published 10 June 2008

CVE-2008-0960: SNMPv3 HMAC verification flaw allows authentication bypass

Juniper · Session And Resource Control

SNMPv3 HMAC verification in multiple products relies on the client to specify the HMAC length, so an attacker can send a length value of 1 and have only the first byte of the digest checked. This lets a remote, unauthenticated attacker bypass SNMP authentication on affected implementations. The flaw is in the protocol handling logic, not a single vendor's code, so exposure depends on which SNMP stack a product uses.

10.0 CVSS 2.0 High EPSS 69% · top 0.7% CWE-287 · Improper authentication
10.0CVSS 2.0 base score
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
128References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 2.0 base score is 10 with network reachability, no authentication and complete impact, and the flaw is a protocol-level authentication bypass affecting many products.

What it is

SNMPv3 HMAC verification in multiple products relies on the client to specify the HMAC length, so an attacker can send a length value of 1 and have only the first byte of the digest checked. This lets a remote, unauthenticated attacker bypass SNMP authentication on affected implementations. The flaw is in the protocol handling logic, not a single vendor's code, so exposure depends on which SNMP stack a product uses.

Impact

An attacker gains unauthenticated access to SNMP-managed devices, which can expose configuration and status data and, depending on the device, allow configuration changes. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.

Attack surface

Reachable over the network via SNMPv3 traffic to the affected agent or service; no authentication is required because the flaw is in the authentication check itself. No user interaction is needed.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.6879, 99.31st percentile), but the reference list contains only vendor advisories and no exploit-tagged references, so public exploit availability is not confirmed by this record.

What to do

  • Apply vendor patches for each affected product; for Net-SNMP upgrade to 5.2.4.1, 5.3.2.1 or 5.4.1.1 or later as applicable.
  • Where patching is not immediately possible, restrict SNMP access to trusted management networks and block UDP 161/162 from untrusted sources.
  • Disable SNMPv3 on devices that do not require it, or fall back to a hardened SNMPv2c configuration with strong community strings and ACLs.
  • Inventory all SNMP-enabled devices and map them to the affected product list to confirm which need patching.

Detection

  • Monitor SNMPv3 traffic for malformed or unusually short HMAC parameters, particularly authentication parameter lengths of 1.
  • Alert on SNMP authentication failures followed by successful requests from the same source, which can indicate bypass attempts.
  • Baseline normal SNMP source addresses and flag SNMP requests from hosts outside management subnets.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html
http://lists.ingate.com/pipermail/productinfo/2008/000021.html
http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00000.html
http://marc.info/?l=bugtraq&m=127730470825399&w=2
http://rhn.redhat.com/errata/RHSA-2008-0528.html
http://secunia.com/advisories/30574 Vendor Advisory
http://secunia.com/advisories/30596 Vendor Advisory
http://secunia.com/advisories/30612
http://secunia.com/advisories/30615 Vendor Advisory
http://secunia.com/advisories/30626 Vendor Advisory
http://secunia.com/advisories/30647 Vendor Advisory
http://secunia.com/advisories/30648 Vendor Advisory
http://secunia.com/advisories/30665 Vendor Advisory
http://secunia.com/advisories/30802 Vendor Advisory
http://secunia.com/advisories/31334 Vendor Advisory
http://secunia.com/advisories/31351 Vendor Advisory
http://secunia.com/advisories/31467 Vendor Advisory
http://secunia.com/advisories/31568 Vendor Advisory
http://secunia.com/advisories/32664 Vendor Advisory
http://secunia.com/advisories/33003 Vendor Advisory
http://secunia.com/advisories/35463
http://security.gentoo.org/glsa/glsa-200808-02.xml
http://securityreason.com/securityalert/3933
http://sourceforge.net/forum/forum.php?forum_id=833770
http://sourceforge.net/tracker/index.php?func=detail&aid=1989089&group_id=12694&atid=456380
http://sunsolve.sun.com/search/document.do?assetkey=1-26-238865-1
http://support.apple.com/kb/HT2163
http://support.avaya.com/elmodocs2/security/ASA-2008-282.htm
http://www.cisco.com/warp/public/707/cisco-sa-20080610-snmpv3.shtml Vendor Advisory
http://www.debian.org/security/2008/dsa-1663 Patch
http://www.kb.cert.org/vuls/id/878044 US Government Resource
http://www.kb.cert.org/vuls/id/CTAR-7FBS8Q US Government Resource
http://www.kb.cert.org/vuls/id/MIMG-7ETS5Z US Government Resource
http://www.kb.cert.org/vuls/id/MIMG-7ETS87 US Government Resource
http://www.mandriva.com/security/advisories?name=MDVSA-2008:118
http://www.ocert.org/advisories/ocert-2008-006.html
http://www.openwall.com/lists/oss-security/2008/06/09/1
http://www.redhat.com/support/errata/RHSA-2008-0529.html
http://www.securityfocus.com/archive/1/493218/100/0/threaded
http://www.securityfocus.com/archive/1/497962/100/0/threaded

Track CVE-2008-0960 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2021-31381Juniper session and resource control information exposure vulnerabilityA configuration weakness in the JBoss Application Server (AppSvr) component of Juniper Networks SRC Series allows a remote attacker to send a special…EPSS 1.2%5.3CVE-2021-31380Juniper session and resource control information exposure vulnerabilityA configuration weakness in the JBoss Application Server (AppSvr) component of Juniper Networks SRC Series allows a remote attacker to send a special…EPSS 1.1%5.3CVE-2021-31352Juniper session and resource control information exposure vulnerabilityAn Information Exposure vulnerability in Juniper Networks SRC Series devices configured for NETCONF over SSH permits the negotiation of weak ciphers,…EPSS 0.83%7.5CVE-2026-42018JFrog Artifactory improper authentication leaks anonymous tokenJFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token …KEVEPSS 9.8%analysed9.8CVE-2026-82329JFrog Artifactory improper authentication allows admin takeoverJFrog Artifactory contains an improper authentication weakness (CWE-287) that, under default configuration, may let an unauthenticated attacker with …KEVEPSS 14%analysed8.8CVE-2026-59822LiteLLM MCP endpoint auth bypass via OAuth2 passthrough fallbackLiteLLM's MCP Streamable HTTP endpoint, prior to 1.84.0, let an unauthenticated attacker send a fabricated Authorization header that triggered an OAu…KEVEPSS 0.84%analysed10.0CVE-2026-49869Kestra OSS auth bypass via path suffix match enables RCEKestra OSS AuthenticationFilter whitelists the public config endpoint using request.getPath().endsWith("/configs"), a suffix match instead of an exac…KEVEPSS 2.1%analysed9.8CVE-2023-49105ownCloud Server WebDAV authentication bypass via pre-signed URLsownCloud core before 10.13.1 accepts pre-signed URLs even when the file owner has no signing-key configured, so the signature check is effectively sk…KEVEPSS 43%analysed

Source: NIST National Vulnerability Database (record CVE-2008-0960), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.