NET1665 - The network device must not use the default or well-known SNMP community strings public and private - SNMPv3 public

Information

Network devices may be distributed by the vendor pre-configured with an SNMP agent using the well-known SNMP community strings public for read only and private for read and write authorization. An attacker can obtain information about a network device using the read community string "public". In addition, an attacker can change a system configuration using the write community string "private".

Solution

Configure unique SNMP community strings replacing the default community strings.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Infrastructure_Router_L3_Switch_V8R27_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5, CAT|I, Rule-ID|SV-3210r4_rule, STIG-ID|NET1665, Vuln-ID|V-3210

Plugin: Juniper

Control ID: e32d3376e2c23c7818a806cfa8566628216ead9b62b5cd95b8271db59288c7f7