NET0894 - Network element must only allow SNMP read access - 'SNMP v3 priv|noauth'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The network device must only allow SNMP read-only access.

Enabling write access to the device via SNMP provides a mechanism that can be exploited by an attacker to set configuration variables that can disrupt network operations.

NOTE: SNMPv3 not found. This check is not applicable.

Solution

Configure the network device to allow for read-only SNMP access when using SNMPv1, v2c, or basic v3 (no authentication or privacy). Write access may be used if authentication is configured when using SNMPv3.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_L2_Switch_V8R27_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CAT|II, CSCv6|3.1, Rule-ID|SV-30086r3_rule, STIG-ID|NET0894, Vuln-ID|V-3969

Plugin: Cisco

Control ID: 78af4fdf5a4fa6992ed82d5305978285a8425e60f8fe41c8f3b6e2aab3564a68