Multiple Vendor HMAC Authentication SNMPv3 Authentication Bypass
Critical Nessus Plugin ID 40449
SynopsisThe SNMP server running on this host is affected by an authentication bypass vulnerability.
DescriptionSNMPv3 HMAC verification relies on the client to specify the HMAC length. This makes it possible for remote attackers to bypass SNMP authentication via repeated attempts with a HMAC length value of 1, which causes only the first byte of the authentication hash to be checked.
This issue affects SNMP implementations from multiple vendors.
SolutionThis vulnerability affects multiple products from multiple vendors. Check with your vendor for the appropriate solution.