1.5.2 Unset 'private' for 'snmp-server community'

Information

An SNMP community string permits read-only access to all objects.

Rationale:

The default community string 'private' is well known. Using easy to guess, well known community string poses a threat that an attacker can effortlessly gain unauthorized access to the device.

Solution

Disable the default SNMP community string 'private'


hostname(config)#no snmp-server community {private}

Impact:

To reduce the risk of unauthorized access, Organizations should disable default, easy to guess, settings such as the 'private' setting for snmp-server community.

References:

http://www.cisco.com/en/US/docs/ios-xml/ios/snmp/command/nm-snmp-cr-s2.html#GUID-2F3F13E4-EE81-4590-871D-6AE1043473DE

See Also

https://workbench.cisecurity.org/files/2585

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5, CSCv6|9.1

Plugin: Cisco

Control ID: 52cbbda7e8bd70b6f87f2764beda6545fb27e8d93b23e9d5e31f25a818699d67