SOL-11.1-080160 - SNMP default community strings and passphrases must be changed from vendor defaults.

Information

Whether active or not, default SNMP passwords, users, and passphrases must be changed to maintain security. If the service is running with the default authenticators, then anyone can gather data about the system and the network and use the information to potentially compromise the integrity of the system or network(s).

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

The root role is required.

Stop the SNMP service:
# svcadm disable svc: /application/management/net-snmp:default

Open the /etc/snmp/snmpd.conf file and remove any lines containing default values.
# pfedit [/path/filename]

Create a new SNMPv3 user with strong authentication and privacy keys (if the service is required).

Restart the service (if the service is required).
# svcadm enable svc: /application/management/net-snmp:default

Ensure permissions on the configuration files are restricted:
# chmod 600 /etc/snmp/snmp.conf

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_11_SPARC_V3R6_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|I, CCI|CCI-000366, Rule-ID|SV-216456r1190826_rule, STIG-ID|SOL-11.1-080160, STIG-Legacy|SV-60867, STIG-Legacy|V-47995, Vuln-ID|V-216456

Plugin: Unix

Control ID: 006110c96b9a3cd8b6c4d7eef8249e50e789d7d15313b1b062cb4957d9439eda