CERT warns of SNMP vulnerability with widespread impact
Home Up About Us Contents Search

Home

                           

CERT warns of SNMP vulnerability with widespread impact

By Ellen Messmer
Network World Fusion, 02/12/02

The CERT Coordination Center has warned that a broad array of network equipment used on the Internet -- including switches, routers, hubs, printers and operating systems -- may be vulnerable to an SNMP-related attack that could cause equipment to fail or allow an attacker to take control of it.

The problem relates to half-dozen vulnerabilities discovered in Simple Network Management Protocol (SNMP) v1, a fundamental IP-based protocol for managing networks. The vulnerabilities, detailed in a paper published by researchers at Finland's Oulu University, reveal precisely how SNMPv1, which is widely used by the network industry, can be exploited to disrupt systems through a denial-of-service attack or to allow a hacker to gain control of equipment.

"Basically, most everything on the Internet is impacted," commented Chris Rouland, director of Internet Security Systems' threat-assessment group, called the X-Force. "Linux, Solaris, BSD, routers, switches, hubs -- this is the most widespread security vulnerability I can ever remember being reported."

The very long list of equipment known to be vulnerable to the SNMP vulnerability problem is detailed on CERT's Web site.

Cisco Systems is expected to soon issue a security advisory regarding the status of its equipment, but security experts believe Cisco's switches, hubs and routers are vulnerable to the SNMPv1 vulnerability. Cisco could not be reached for comment.

Attackers could exploit technical weaknesses related to six classes of vulnerability -- overflow exceptions, format-string exceptions, bit-pattern exceptions, basic encoding rules, missing symbol exceptions and integral-value exceptions -- to knock equipment offline or gain control of it.

The Finnish university published Java-based tools to demonstrate some of these attacks, Rouland noted. "Today, it's only the denial-of-service stuff. But someone will write the exploits for broader attacks to control systems," Rouland said.

About 40 vendors, which are said to have known of the issue for a few weeks, have reported to CERT so far. AdventNet, Avaya, cacheFlow, 3Com and Caldera have all detailed products which are vulnerable. Computer Associates acknowledged its Unicenter management platform is vulnerable. Systems running Hewlett-Packard's HP-UX operating system and snmpd or OpenView are vulnerable. Some versions of Microsoft are affected, although not Windows XP. The list goes on for 20 pages.

A few vendors reported their products are not vulnerable, such as IBM's AIX or products from Covalent Technologies.

With the network industry discussing this problem quietly as it could for two weeks, most vendors have software patches available or plans in the works to ready them.

Some products come with SNMPv1 turned on by default. Security experts are recommending turning off SNMP or blocking SNMP traffic that does not originate directly under corporate network-management control.

"It would take a very skilled hacker to exploit some of these vulnerabilities," said Guardent Chief Technology Officer Jerry Brady.

But as a precaution, Guardent, which provides security management services for 300 companies, decided to prevent SNMP traffic from untrusted systems from reaching trusted systems in the corporate environment. "We're providing 'triage' support here, by blocking the protocol entirely," Brady said. Guardent will maintain that approach until customer equipment is patched and tested for resistance to the SNMP vulnerabilities.

Brady said he expects it may be difficult to install a software patch on systems such as routers, and like many managers he's awaiting word from Cisco on how the SNMPv1 problem affects Cisco equipment.

ISS's Chris Rouland advised ensuring that any device that uses SNMPv1 be configured to only allow SNMP traffic from the network management console used to manage it. ISS has also prepared signature updates for its intrusion-detection and scanning products to recognize this new vulnerability.

If users or service providers experience unexplained disruptions in equipment, they are urged to call the CERT hotline at 412-268-7090.

While there's little sign yet that attackers are exploiting the vulnerabilities -- perhaps because they are somewhat difficult to understand even by reading the Finnish university paper on the topic -- that could change now that there's more widespread publicity about the SNMPv1 issues.

"The biggest risk may be for home users with cable and DSL that are directly on the Internet," said Rouland. Hackers will find them to be one of the easiest targets, he predicted.

Related links

Contact Senior Editor Ellen Messmer

Other recent articles by Messmer

The CERT advisory

Reaction: Here's what some Fusion users are saying about this article:   There is an error in this article   Changed

What do you think? Add your comments to the thread

Forum: The SNMP hole
What are you doing about the newly discovered hole in this key protocol?

Network World Security and Bug Patch Alert
Sign up for our free e-mail newsletter.

Breaking security-hole news

Microsoft battles security holes with IE patch
02/12/02
The 'cumulative' patch made available for download Monday fixes holes in Versions 5.01, 5.5 and 6.0 of Internet Explorer.

 

MSN Messenger vulnerable through IE bug
02/11/02
A malicious Web site operator can hijack a user's MSN Messenger application and perform all tasks, including sending messages and personal files, according to a bulletin posted on the Bugtraq mailing list on Saturday and a warning issued by security software firm Finjan Software on Sunday.

 

Security holes found in Oracle software
02/07/02
Several security flaws were discovered in the company's software, including one that could allow a hacker to gain access to Oracle's database server without a user ID or password.

 

Oracle 9i database flaws found , 02/06/02
02/06/02
Today's bug patches and security alerts:

 

‘Knockout’ disaster recovery advice , 02/04/02
02/04/02
One of my favorite commercials during the Super Bowl was for Computer Associate's BrightStor product. The ad featured two CEO underlings, the guys with all ...

More articles

 

Click below for more developments and tutorial articles:

 

Home ] Up ]

Send mail to webmaster@infomatek.com with questions or comments about this web site.
Copyright © 2001 Infomatek Consulting and Marketing Services