UCSF home page UCSF home About UCSF Search UCSF UCSF Medical Center

image of letter Email

blank Access mail@ucsf
blank Update spam filter
blank Reset password

image of lock VPN

blank Login to vpn@ucsf
blank VPN Help

image of phone Help

blank Login to help@ucsf
blank email us
blank Call (415) 514-4100,
blank Option 2




Advanced Search
Recent Changes

Critical Security Alert: SNMPv3 Authentication Bypass Vulnerability

SECURITY UPDATE:

The United States Computer Emergency Readiness Team (US-CERT) reported a vulnerability in the way implementations of Simple Network Management Protocol (SNMP)v3 handles specially crafted packets.  SNMP is a widely deployed protocol that is commonly used to monitor and manage network devices.

This vulnerability allows attackers to read and modify any SNMP object that can be accessed using the authentication credentials that got them into the system. Attackers exploiting this vulnerability can view and modify the configuration of these devices.

NOTE:  Attackers must gain access using credentials with write privileges in order to modify configurations.

For a complete description of the vulnerability, refer to US-CERT's “Technical Cyber Security Alert TA08-162A." 

AFFECTED SOFTWARE:
Multiple Implementations of SNMPv3

SOLUTION:

ADDITIONAL INFORMATION:

Enterprise Information Security
http://security.ucsf.edu 

US-CERT Technical Cyber Security Alerts
http://www.us-cert.gov/cas/techalerts/

Please tell us what you think of our website