HP OpenView EMANATE SNMP Agent predictable default SNMP community string

hp-emanate-default-snmp (9814) The risk level is classified as HighHigh Risk

Description:

HP OpenView EMANATE (Enhanced MANagement Agent Through Extensions) SNMP (Simple Network Management Protocol) Agent uses a predictable default SNMP community string. A remote attacker could exploit this vulnerability to gain unauthorized SNMP access and possibly crash the affected device.


Consequences:

Gain Access

Remedy:

Apply the appropriate patch for your system, as listed in Hewlett-Packard Company Security Bulletin HPSBUX0208-208. See References.

References:

  • Hewlett-Packard IT Resource Center Forums: Security vulnerability in the Emanate SNMP agent version 14.2 supplied with NNM.
  • BID-5428: HP EMANATE 14.2 Predictable SNMP Community String Vulnerability
  • CVE-2002-1408: Unknown vulnerability or vulnerabilities in HP OpenView EMANATE 14.2 snmpModules allow the SNMP read-write community name to be exposed, related to (1) read-only community access

Platforms Affected:

  • HP OpenView Emanate SNMP Agent 14.2

Reported:

Aug 08, 2002

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page