1.5.1 Unset 'private' for 'snmp-server community'

Information

An SNMP community string permits read-only access to all objects.

The default community string "private" is well known. Using easy to guess, well known community string poses a threat that an attacker can effortlessly gain unauthorized access to the device.

Solution

Disable the default SNMP community string private

IOSXR(config)#no snmp-server community {community_string}

Impact:

To reduce the risk of unauthorized access, Organizations should disable default, easy to guess, settings such as the 'private' setting for snmp-server community.

See Also

https://workbench.cisecurity.org/benchmarks/10473

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CA-9, 800-53|SC-7, 800-53|SC-7(5), CSCv7|9.2

Plugin: Cisco

Control ID: 0815e539601f18061790345fdfb621c42f5f844d67390a7aaa9c6f72e7b9db68