Free DISA STIG and SRG Library | Vaulted

V-3969

Network devices must only allow SNMP read-only access.

Finding ID
NET0894
Rule ID
SV-3969r5_rule
Severity
Cat II
CCE
(None)
Group Title
Network element must only allow SNMP read access.
CCI
(None)
Target Key
(None)
Documentable
No
Discussion

Enabling write access to the device via SNMP provides a mechanism that can be exploited by an attacker to set configuration variables that can disrupt network operations.

Fix Text

Configure the network device to allow for read-only SNMP access when using SNMPv1, v2c, or basic v3 (no authentication or privacy). Write access may be used if authentication is configured when using SNMPv3.

Check Content

Review the network device configuration and verify SNMP community strings are read-only when using SNMPv1, v2c, or basic v3 (no authentication or privacy). Write access may be used if authentication is configured when using SNMPv3. If write-access is used for SNMP versions 1, 2c, or 3-noAuthNoPriv mode and there is no documented approval by the ISSO, this is a finding.

Responsibility

Information Assurance Officer