NET1665 - The network device must not use the default or well-known SNMP community strings public and private.

Information

Network devices may be distributed by the vendor pre-configured with an SNMP agent using the well-known SNMP community strings public for read only and private for read and write authorization. An attacker can obtain information about a network device using the read community string 'public'. In addition, an attacker can change a system configuration using the write community string 'private'.

Solution

Configure unique SNMP community strings replacing the default community strings.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Firewall_V8R24_STIG.zip

Item Details

References: CAT|I, Rule-ID|SV-3210r4_rule, STIG-ID|NET1665, Vuln-ID|V-3210

Plugin: Cisco

Control ID: 83f119437ba0e963f3ae811d991b6b5bd844bf09cc46ada10078b3a878f89bb8