{
    "id": "CVE-2008-0960",
    "published": "2008-06-10 18:32:00",
    "last_modified": "2026-06-16 22:50:41",
    "cvss_score": "10.0",
    "cvss_severity": "HIGH",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
    "cwe": "CWE-287",
    "description": "SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.",
    "epss_score": "0.68790",
    "epss_percentile": "0.99326",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-09-27 18:17:07",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "cisco",
            "product": "ace_10_6504_bundle_with_4_gbps_throughput"
        },
        {
            "vendor": "cisco",
            "product": "ace_10_6509_bundle_with_8_gbps_throughput"
        },
        {
            "vendor": "cisco",
            "product": "ace_10_service_module"
        },
        {
            "vendor": "cisco",
            "product": "ace_20_6504_bundle_with__4gbps_throughput"
        },
        {
            "vendor": "cisco",
            "product": "ace_20_6509_bundle_with_8gbps_throughput"
        },
        {
            "vendor": "cisco",
            "product": "ace_20_service_module"
        },
        {
            "vendor": "cisco",
            "product": "ace_4710"
        },
        {
            "vendor": "cisco",
            "product": "ace_xml_gateway"
        },
        {
            "vendor": "cisco",
            "product": "catos"
        },
        {
            "vendor": "cisco",
            "product": "cisco_ios"
        },
        {
            "vendor": "cisco",
            "product": "ios"
        },
        {
            "vendor": "cisco",
            "product": "ios_xr"
        },
        {
            "vendor": "cisco",
            "product": "mds_9120"
        },
        {
            "vendor": "cisco",
            "product": "mds_9124"
        },
        {
            "vendor": "cisco",
            "product": "mds_9134"
        },
        {
            "vendor": "cisco",
            "product": "mds_9140"
        },
        {
            "vendor": "cisco",
            "product": "nx_os"
        },
        {
            "vendor": "ecos_sourceware",
            "product": "ecos"
        },
        {
            "vendor": "ingate",
            "product": "ingate_firewall"
        },
        {
            "vendor": "ingate",
            "product": "ingate_siparator"
        },
        {
            "vendor": "juniper",
            "product": "session_and_resource_control"
        },
        {
            "vendor": "juniper",
            "product": "src_pe"
        },
        {
            "vendor": "net-snmp",
            "product": "net_snmp"
        },
        {
            "vendor": "sun",
            "product": "solaris"
        },
        {
            "vendor": "sun",
            "product": "sunos"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "5790",
            "title": "SNMPv3 - HMAC Validation error Remote Authentication Bypass",
            "date": "2008-06-12",
            "url": "https://www.exploit-db.com/exploits/5790"
        }
    ],
    "refs_list": [
        "http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html",
        "http://lists.ingate.com/pipermail/productinfo/2008/000021.html",
        "http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00000.html",
        "http://marc.info/?l=bugtraq&m=127730470825399&w=2",
        "http://rhn.redhat.com/errata/RHSA-2008-0528.html",
        "http://secunia.com/advisories/30574",
        "http://secunia.com/advisories/30596",
        "http://secunia.com/advisories/30612",
        "http://secunia.com/advisories/30615",
        "http://secunia.com/advisories/30626",
        "http://secunia.com/advisories/30647",
        "http://secunia.com/advisories/30648",
        "http://secunia.com/advisories/30665",
        "http://secunia.com/advisories/30802",
        "http://secunia.com/advisories/31334",
        "http://secunia.com/advisories/31351",
        "http://secunia.com/advisories/31467",
        "http://secunia.com/advisories/31568",
        "http://secunia.com/advisories/32664",
        "http://secunia.com/advisories/33003",
        "http://secunia.com/advisories/35463",
        "http://security.gentoo.org/glsa/glsa-200808-02.xml",
        "http://securityreason.com/securityalert/3933",
        "http://sourceforge.net/forum/forum.php?forum_id=833770",
        "http://sourceforge.net/tracker/index.php?func=detail&aid=1989089&group_id=12694&atid=456380"
    ]
}