PROTOCOL-SNMP -- Snort has detected traffic that may indicate the presence of the snmp protocol or vulnerabilities in the snmp protocol on the network.
PROTOCOL-SNMP PROTOS test-suite-req-app attempt
This event is generated when an attempt is made to attack a device using SNMP v1. Impact: Varies depending on the implementation. Ranges from Denial of Service (DoS) to code execution. Details: SNMP is a widely adopted protocol for managing IP networks, including individual network devices, and devices in aggregate. Several network devices come pre-installed with this protocol for management and monitoring. A number of vulnerabilities exist in SNMP v1, including a community string buffer overflow, that will allow an attacker to execute arbitrary code or shutdown the service. Ease of Attack: Simple.
No information provided
No public information
No known false positives
Cisco Talos Brian Caswell Nigel Houghton Snort documentation contributed by Nawapong Nakjang (tony@ksc.net, tonie@thai.com)
No rule groups
None
No information provided
None