Information
If snmpd is required within the environment, disable or change the public community string.
Rationale:
The public community string can be polled by remote SNMP devices and pertinent information can be read or changed on the host. The public community string should but commented out, or if SNMP is a required service the public community name should be changed to be a combination of letters, numbers and special characters to enhance security.
Solution
Edit the file:
vi /etc/snmpd.conf
Comment out the public entry:
#community public
Default Value:
Commented in
Additional Information:
Reversion:
Copy back the original /etc/snmpd.conf file:
cp -p /etc/snmpd.conf.pre_cis /etc/snmpd.conf