PT-2009-2564 · Aruba · Arubaos

Published

2009-08-27

·

Updated

2018-10-11

·

CVE-2008-7095

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions ArubaOS version 3.3.2.6
Description The issue concerns the SNMP daemon, which does not properly restrict SNMP access. This allows remote attackers to read all SNMP community strings via SNMP-COMMUNITY-MIB::snmpCommunityName (1.3.6.1.6.3.18.1.1.1.2) or SNMP-VIEW-BASED-ACM-MIB::vacmGroupName (1.3.6.1.6.3.16.1.2.1.3) with knowledge of one community string. Additionally, attackers can read SNMPv3 user names via SNMP-USER-BASED-SM-MIB or SNMP-VIEW-BASED-ACM-MIB.
Recommendations As a temporary workaround, consider restricting SNMP access until a patch is available. Restrict access to the SNMP daemon to minimize the risk of exploitation. Avoid using the snmpCommunityName and vacmGroupName variables in the affected MIBs until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-7095

Affected Products

Arubaos