SNMP Version 3 Authentication Vulnerabilities

Multiple Cisco products contain either of two authentication vulnerabilities in the Simple Network Management Protocol version 3 (SNMPv3) feature. These vulnerabilities can be exploited when processing a malformed SNMPv3 message. These vulnerabilities could allow the disclosure of network information or may enable an attacker to perform configuration changes to vulnerable devices. The SNMP server is an optional service that is disabled by default in Cisco products. Only SNMPv3 is impacted by these vulnerabilities. Workarounds are available for mitigating the impact of the vulnerabilities described in this document.

Vulnerable products:
# Cisco IOS
# Cisco IOS-XR
# Cisco Catalyst Operating System (CatOS)
# Cisco NX-OS
# Cisco Application Control Engine (ACE) Module
# Cisco ACE Appliance
# Cisco ACE XML Gateway
# Cisco MDS 9000 Series Multilayer Fabric Switches
# Cisco Wireless LAN Controller (WLC)
# Cisco Application and Content Networking System (ACNS)
# Cisco Wide Area Application Services (WAAS)
# Cisco MGX 8850, 8880 Media Gateway and Switch
# Cisco PSTN Gateway (PGW2200)

Read more on Cisco Security Advisory

Published by


Calin is a network engineer, with more than 20 years of experience in designing, installing, troubleshooting, and maintaining large enterprise WAN and LAN networks.

2 thoughts on “SNMP Version 3 Authentication Vulnerabilities”

  1. I’ve glanced at some of your posts and I was wondering if you were interesting in swapping webpage links? I am constantly wanting to trade links with websites about related content! I look forward to hearing back from you before long.

Any opinion on this post? Please let me know:

This site uses Akismet to reduce spam. Learn how your comment data is processed.