The default passwords and SNMP community strings of all management services have not been replaced with complex passwords.

From Multifunction Device and Network Printers STIG

Part of MFD SNMP Community Strings

SV-7003r2_rule The default passwords and SNMP community strings of all management services have not been replaced with complex passwords.

Vulnerability discussion

There are many known vulnerabilities in the SNMP protocol and if the default community strings and passwords are not modified an unauthorized individual could gain control of the MFD or printer. This could lead to a denial of service or the compromise of sensitive data.The SA will ensure the default passwords and SNMP community strings of all management services are replaced with complex passwords.

Check content

The reviewer will, with assistance from the SA, verify the default passwords and SNMP community strings of all management services have been replaced with complex passwords.

Fix text

Develop a plan to coordinate the modification of the default passwords and SNMP community strings of all management services replacing them with complex passwords. Obtain CM approval of the plan and execute the plan.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer