CVE-2008-7095

ArubaOS 3.3.2.6 - Unauthenticated SNMP Information Disclosure

Title source: llm
STIX 2.1

Description

The SNMP daemon in ArubaOS 3.3.2.6 in Aruba Mobility Controller does not restrict SNMP access, which allows remote attackers to (1) read all SNMP community strings via SNMP-COMMUNITY-MIB::snmpCommunityName (1.3.6.1.6.3.18.1.1.1.2) or SNMP-VIEW-BASED-ACM-MIB::vacmGroupName (1.3.6.1.6.3.16.1.2.1.3) with knowledge of one community string, and (2) read SNMPv3 user names via SNMP-USER-BASED-SM-MIB or SNMP-VIEW-BASED-ACM-MIB.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/498033/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/51916
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/32102

Scores

EPSS 0.0030
EPSS Percentile 53.7%

Details

CWE
CWE-264
Status published
Products (2)
arubanetworks/aruba_mobility_controller
arubanetworks/arubaos 3.3.2.6
Published Aug 27, 2009
Tracked Since Feb 18, 2026