SNMP Agent Default Community Name (public)

This script is Copyright (C) 2009-2012 Tenable Network Security, Inc.


Synopsis :

The community name of the remote SNMP server can be guessed.

Description :

It is possible to obtain the default community name of the remote
SNMP server.

An attacker may use this information to gain more knowledge about the
remote host, or to change the configuration of the remote system (if
the default community allows such modifications).

Solution :

Disable the SNMP service on the remote host if you do not use it.
Either filter incoming UDP packets going to this port, or change the
default community string.

Risk factor :

High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 7.1
(CVSS2#E:F/RL:U/RC:ND)

Family: SNMP

Nessus Plugin ID: 41028 ()

Bugtraq ID: 2112

CVE ID: CVE-1999-0517