SNMP_Missing community string attempt

 

Code: p556

Severity: Warning

 

Description: This event is generated when SNMP communications do not contain a community name.

Impact: Medium to Serious. Depending on if the community string was for read-only, read-create or read-write an attacker could gain a varying level of access to a system.

Corrective: Ensure that all devices using SNMP have a community string assigned. Make sure that all devices that have SNMP turned on have complex passwords assigned. Disable unneeded WRITE / CREATE community strings. Since SNMP traffic is not encrypted, use a packet filtering firewall to restrict SNMP communications to the protected network.