Rule Category

PROTOCOL-SNMP -- Snort has detected traffic that may indicate the presence of the snmp protocol or vulnerabilities in the snmp protocol on the network.

Alert Message

PROTOCOL-SNMP public access tcp

Rule Explanation

This rule looks for SNMP traffic that includes the default community string "public", which could be indicative of attempts to enumerate or manipulate device information via SNMP.

What To Look For

This rule fires on attempts to use the default SNMP community string on SNMP servers.

Known Usage

No public information

False Positives

Known false positives, with the described conditions

Potential false positives due to legitimate SNMP traffic using the default community string

Contributors

Cisco Talos Intelligence Group

Rule Groups

MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application

Vulnerability::Severity::High

Vulnerability::Severity::Critical

MITRE::ATT&CK Framework::Enterprise::Reconnaissance::Gather Victim Host Information

Rule Categories::Protocol::SNMP

MITRE::ATT&CK Framework::Enterprise::Discovery::Remote System Discovery

CVE

Rule Vulnerability

N/A

Not Applicable

CVE Additional Information

This product uses data from the NVD API but is not endorsed or certified by the NVD.
CVE-1999-0517
Loading description
CVE-2002-0012
Loading description
CVE-2002-0013
Loading description