ESXI-70-000053 - Simple Network Management Protocol (SNMP) must be configured properly on the ESXi host.

Information

If SNMP is not being used, it must remain disabled. If it is being used, the proper trap destination must be configured. If SNMP is not properly configured, monitoring information can be sent to a malicious host that can use this information to plan an attack.

Solution

To disable SNMP from an ESXi shell, run the following command:

# esxcli system snmp set -e no

or

From a PowerCLI command prompt while connected to the ESXi Host:

Get-VMHostSnmp | Set-VMHostSnmp -Enabled $false

To configure SNMP for v3 targets, use the 'esxcli system snmp set' command set locally on the host or remotely via PowerCLI.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_vSphere_7-0_Y23M07_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-256414r886023_rule, STIG-ID|ESXI-70-000053, Vuln-ID|V-256414

Plugin: VMware

Control ID: be201b863ee6866945c85322c0bcfebd3e4dafc735df18601a0304fd8fa81256