Answer the question
In order to leave comments, you need to log in
How to disable the public account for SNMP?
Hello!
The situation is as follows:
MaxPatrol, if anyone is familiar with such a vulnerability scanner, issued the following:
Vulnerable nodes
192.168.1.50
IP address 192.168.1.50
Name from task 192.168.1.50
161/UDP • SNMP
Protocol versions: 1
Account
public
Information
Xerox DocuPrint N2825 Network Laser Printer - 2.12-02
There are other printers, but I would like to understand the essence of the problem using this example.
If you go to the web interface of the printer, then there is only a brief info on SNMP, but there is no public account and nothing can be configured, much less deleted.
However, if you go to the properties of this printer on the computer, then there in the TCP / IP Port setting, there is a checkmark: SNMP status is allowed , and below the public account flaunts , for some reason it is called " Community Name " there.
In short, of course, you can disable this setting, but you need to do this on each computer and when installing on a new one, go into the settings and remove it.
The question is, is it possible to somehow remove this account on the printer itself (I searched - I didn’t find it) or the only option is to remove it on all computers, and most importantly, how will MaxPatrol react to this later? In the description of the vulnerability, there is not a word about the fact that this public account is available on this and that computer, it turns out that most likely it scans the printer itself, and then it’s not at all clear what to do?
Answer the question
In order to leave comments, you need to log in
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question