NET1665 - Using default SNMP community names - 'Community set to Public or Private'

Information

The network element must not use the default or well-known SNMP community strings public and private.

Network elements may be distributed by the vendor pre-configured with an SNMP agent using the well known SNMP community strings public for read only and private for read and write authorization. An attacker can obtain information about a network element using the read community string 'public'. In addition, an attacker can change a system configuration using the write community string 'private'.

Solution

Configure unique SNMP community strings replacing the default community strings.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Infrastructure_Router_L3_Switch_V8R29_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5, CAT|I, CSCv6|5.3, Rule-ID|SV-3210r4_rule, STIG-ID|NET1665, Vuln-ID|V-3210

Plugin: Cisco

Control ID: bd7d0b5292556557e9138665570cbcec5ef0204f78d0e5d9278351f10d04eda8