Rule Category

PROTOCOL-SNMP -- Snort has detected traffic that may indicate the presence of the snmp protocol or vulnerabilities in the snmp protocol on the network.

Alert Message

PROTOCOL-SNMP PROTOS test-suite-req-app attempt

Rule Explanation

This event is generated when an attempt is made to attack a device using SNMP v1. Impact: Varies depending on the implementation. Ranges from Denial of Service (DoS) to code execution. Details: SNMP is a widely adopted protocol for managing IP networks, including individual network devices, and devices in aggregate. Several network devices come pre-installed with this protocol for management and monitoring. A number of vulnerabilities exist in SNMP v1, including a community string buffer overflow, that will allow an attacker to execute arbitrary code or shutdown the service. Ease of Attack: Simple.

What To Look For

No information provided

Known Usage

No public information

False Positives

No known false positives

Contributors

Cisco Talos Brian Caswell Nigel Houghton Snort documentation contributed by Nawapong Nakjang (tony@ksc.net, tonie@thai.com)

Rule Groups

No rule groups

CVE

None

Additional Links

Rule Vulnerability

No information provided

CVE Additional Information

This product uses data from the NVD API but is not endorsed or certified by the NVD.

None