jim_duffy
Managing Editor

Cisco Security Advisory: holes found, fixed in SNMP Version 3 authentication

Analysis
Jun 10, 20081 min

Cisco Security sent out an advisory today warning that multiple Cisco products contain one of two authentication vulnerabilities in the

Simple Network Management Protocol version 3 (SNMPv3) feature. The holes can be exploited when processing a malicious SNMPv3 message and could allow the attacker to obtain network information or even perform configuration changes to vulnerable devices. The good news is that SNMP server is an optional service that is disabled by default in Cisco products, Cisco says, plus only SNMPv3 is impacted. Workarounds are already available. US-CERT has also assigned a Vulnerability Note VU#878044 to these vulnerabilities, Cisco reports.

If you would like more guidance in decrypting Cisco’s Common Vulnerability Scoring System (CVSS), check out a blog post by Micheal Morris that deciphers the somewhat cryptic, but still useful, system.

Go to Cisco Subnet for more Cisco news, blogs, discussion forums, security alerts, book giveaways, and more.More from Cisco Subnet:
Multiple vulnerabilities fixed in PIX and CiscoCisco acquires DiviTech A/S Free books, training, gift certificates — giveaways for June from Cisco Subnet

ASA

iPhone to include Cisco VPN

The Weather Channel goes HD with Cisco