1.5.3 Unset 'public' for 'snmp-server community'

Information

An SNMP community string permits read-only access to all objects.

Rationale:

The default community string 'public' is well known. Using easy to guess, well known community string poses a threat that an attacker can effortlessly gain unauthorized access to the device.

Impact:

To reduce the risk of unauthorized access, Organizations should disable default, easy to guess, settings such as the 'public' setting for snmp-server community.

Solution

Disable the default SNMP community string 'public'


hostname(config)#no snmp-server community {public}

See Also

https://workbench.cisecurity.org/files/2936

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5, CSCv6|9.1, CSCv7|9.2

Plugin: Cisco

Control ID: a6729b087f61e9ae36dd40b9a32b9cca86d4197ae50e25043393e45e46d172ec