NET1665 - Using default SNMP community names - 'Community set to Public or Private'

Information

The network element must not use the default or well-known SNMP community strings public and private.

Network elements may be distributed by the vendor pre-configured with an SNMP agent using the well known SNMP community strings public for read only and private for read and write authorization. An attacker can obtain information about a network element using the read community string 'public'. In addition, an attacker can change a system configuration using the write community string 'private'.

Solution

Configure unique SNMP community strings replacing the default community strings.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Perimeter_Router_L3_Switch_V8R32_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5, CAT|I, CSCv6|5.3, Rule-ID|SV-3210r4_rule, STIG-ID|NET1665, Vuln-ID|V-3210

Plugin: Cisco

Control ID: 7a896e479851d128445c10b6d327b4bb71a482275e65dc797b596c6938c976ab