4.7.2.18 /var/tmp/snmpd.log

Information

The /var/tmp/snmpd.log is the logfile used by snmpd daemon, and contains network and machine related information.

Rationale:

The /var/tmp/snmpd.log logfile contains sensitive information through which an attacker can find out about the SNMP deployment architecture in your network. This log file must be secured from unauthorized access.

Solution

Remove world read and write from /var/tmp/snmpd.log:

chmod o-rw /var/tmp/snmpd.log

Default Value:

644

See Also

https://workbench.cisecurity.org/benchmarks/13069

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

References: 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|SA-3, 800-53|SA-8, 800-53|SA-10, CSCv7|5.1

Plugin: Unix

Control ID: 0056a2420c63420567ab0161740145c723adfb5a90c3a692651b9d2c1df28276