M-042: Multiple Vulnerabilities in Multiple Implementations of SNMP Privacy and Legal Notice

CIAC ADVISORY NOTICE

M-042: Multiple Vulnerabilities in Multiple Implementations of SNMP

[CERT Advisory CA-2002-03]

February 12, 2002 21:00 GMT
[Revised 13 February 2002]
[Revised 15 February 2002]
[Revised 19 February 2002]
[Revised 25 February 2002]
[Revised  7 March 2002]
[Revised  9 April 2002]
[Revised 25 April 2002]

PROBLEM: The messaging protocol used in the SNMPv1 protocol has been found to be vulnerable to many types of remote attacks including: denial-of-service, unauthorized privilege access, and unstable behavior.
PLATFORM: A list of tested platforms is in the CERT bulletin. However, essentially all platforms that use SNMP are vulnerable. Typical platforms that use SNMP for management include routers, switches, hubs, workstations, and servers. Of particular importance are platforms where SNMP is installed by default.
DAMAGE: Remote users can crash systems, make systems unstable, and gain privileged access to systems.
SOLUTION: Where possible, apply vendor patches. Until patches are available, you should do the following: 1. Block SNMP traffic at the border routers of your network. This includes blocking traffic (TCP and UDP) going in both directions at the border routers for ports 161, 162, 199, 391, 705, and 1993. Blocking the outgoing traffic prevents a site from becoming a source of an attack. 2. Remove or disable SNMP on all border devices. 3. Remove or disable SNMP on any systems that do not need it. 4. Where possible, manage systems with protocols other than SNMP. 5. Filter or segregate internal SNMP traffic to limit access to the SNMP ports on managed systems. 6. Change the default community strings.

VULNERABILITY
ASSESSMENT:
The risk is HIGH. The use of SNMP is widespread within the government, military, and public. Most implementations of SNMP are vulnerable. The vulnerability has been made public. The vulnerabilities can result in remote privileged access to systems.

LINKS:  
  CIAC BULLETIN: http://www.ciac.org/ciac/bulletins/m-042.shtml
  ORIGINAL BULLETIN: http://www.cert.org/advisories/CA-2002-03.html
  VENDOR PATCHES OR WORKAROUNDS:
    N0TE: PLEASE REVIEW CERT'S BULLETIN FOR VENDOR PRODUCT UPDATES AND REVISIONS.

Compaq Computer Corp., Tru64 update (4-9-02)   http://ftp.support.compaq.com/patches/.new/html/SSRT0779.shtml
SGI, IRIX update (4-9-02)   ftp://patches.sgi.com/support/free/security/advisories/20020201-01-P
SGI, IRIX hpsnmpd Vulnerability update (4-25-02)   ftp://patches.sgi.com/support/free/security/advisories/20020404-01-P


CIAC wishes to acknowledge the contributions of CERT Coordination Center for the information contained in this bulletin.
DOE-CIRC can be contacted at:
    Voice:          +1 866-941-2472 (7 x 24)
    E-mail:          doecirc@doecirc.energy.gov
    World Wide Web:  http://www.doecirc.energy.gov/