PROTOCOL-SNMP -- Snort has detected traffic that may indicate the presence of the snmp protocol or vulnerabilities in the snmp protocol on the network.
PROTOCOL-SNMP public access tcp
This rule looks for SNMP traffic that includes the default community string "public", which could be indicative of attempts to enumerate or manipulate device information via SNMP.
This rule fires on attempts to use the default SNMP community string on SNMP servers.
No public information
Known false positives, with the described conditions
Potential false positives due to legitimate SNMP traffic using the default community string
Cisco Talos Intelligence Group
MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application
Vulnerability::Severity::High
Vulnerability::Severity::Critical
MITRE::ATT&CK Framework::Enterprise::Reconnaissance::Gather Victim Host Information
Rule Categories::Protocol::SNMP
MITRE::ATT&CK Framework::Enterprise::Discovery::Remote System Discovery
N/A
Not Applicable
CVE-1999-0517 |
Loading description
|
CVE-2002-0012 |
Loading description
|
CVE-2002-0013 |
Loading description
|