Check: NET0894
WMAN Bridge STIG (STIG):
NET0894
(in versions v6 r13 through v6 r11)
Title
Network devices must only allow SNMP read-only access. (Cat II impact)
Discussion
Enabling write access to the device via SNMP provides a mechanism that can be exploited by an attacker to set configuration variables that can disrupt network operations.
Check Content
Review the network device configuration and verify SNMP community strings are read-only when using SNMPv1, v2c, or basic v3 (no authentication or privacy). Write access may be used if authentication is configured when using SNMPv3. If write-access is used for SNMP versions 1, 2c, or 3-noAuthNoPriv mode and there is no documented approval by the ISSO, this is a finding.
Fix Text
Configure the network device to allow for read-only SNMP access when using SNMPv1, v2c, or basic v3 (no authentication or privacy). Write access may be used if authentication is configured when using SNMPv3.
Additional Identifiers
Rule ID: SV-3969r5_rule
Vulnerability ID: V-3969
Group Title: Network element must only allow SNMP read access.
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |