Vulnerability record · CVE-2008-0960 · published 10 June 2008
CVE-2008-0960: SNMPv3 HMAC verification flaw allows authentication bypass
Juniper · Session And Resource Control
SNMPv3 HMAC verification in multiple products relies on the client to specify the HMAC length, so an attacker can send a length value of 1 and have only the first byte of the digest checked. This lets a remote, unauthenticated attacker bypass SNMP authentication on affected implementations. The flaw is in the protocol handling logic, not a single vendor's code, so exposure depends on which SNMP stack a product uses.
Description
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score is 10 with network reachability, no authentication and complete impact, and the flaw is a protocol-level authentication bypass affecting many products.
What it is
SNMPv3 HMAC verification in multiple products relies on the client to specify the HMAC length, so an attacker can send a length value of 1 and have only the first byte of the digest checked. This lets a remote, unauthenticated attacker bypass SNMP authentication on affected implementations. The flaw is in the protocol handling logic, not a single vendor's code, so exposure depends on which SNMP stack a product uses.
Impact
An attacker gains unauthenticated access to SNMP-managed devices, which can expose configuration and status data and, depending on the device, allow configuration changes. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.
Attack surface
Reachable over the network via SNMPv3 traffic to the affected agent or service; no authentication is required because the flaw is in the authentication check itself. No user interaction is needed.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.6879, 99.31st percentile), but the reference list contains only vendor advisories and no exploit-tagged references, so public exploit availability is not confirmed by this record.
What to do
- Apply vendor patches for each affected product; for Net-SNMP upgrade to 5.2.4.1, 5.3.2.1 or 5.4.1.1 or later as applicable.
- Where patching is not immediately possible, restrict SNMP access to trusted management networks and block UDP 161/162 from untrusted sources.
- Disable SNMPv3 on devices that do not require it, or fall back to a hardened SNMPv2c configuration with strong community strings and ACLs.
- Inventory all SNMP-enabled devices and map them to the affected product list to confirm which need patching.
Detection
- Monitor SNMPv3 traffic for malformed or unusually short HMAC parameters, particularly authentication parameter lengths of 1.
- Alert on SNMP authentication failures followed by successful requests from the same source, which can indicate bypass attempts.
- Baseline normal SNMP source addresses and flag SNMP requests from hosts outside management subnets.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-0960 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-0960), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.