Cisco CCNP Security Core (SCOR) 350-701Network SecurityHard
A security auditor is reviewing the configuration of a network device that uses SNMP for monitoring. The auditor discovers that the device is configured with SNMPv2c and uses a simple community string for authentication. No encryption is configured. What is the most significant security vulnerability associated with this configuration?
- AReplay attacks
- BDenial of service attacks
- CLack of data integrity
- DWeak key exchange
Show answer & explanationAnswer & explanation
Correct answer: C. Lack of data integrity
SNMPv2c uses community strings for authentication, which are sent in plain text over the network. Without encryption, not only is the community string exposed, but the entire SNMP message (including sensitive monitoring data) is also transmitted without any protection against modification. This means an attacker could intercept and alter the data, leading to a lack of data integrity, or even compromise the device by learning the community string.
Why the other options are wrong
- A. Replay attacks are less directly associated with SNMPv2c's core vulnerability compared to the fundamental lack of confidentiality and integrity due to plain-text transmission.
- B. While DoS attacks are possible against SNMP, the primary vulnerability from plain-text community strings and unencrypted traffic is data exposure and manipulation, not DoS.
- D. SNMPv2c does not involve a cryptographic key exchange mechanism like more secure protocols; its weakness is the plain-text community string itself, not a 'weak' exchange.
SNMPv2c Vulnerabilities
SNMPv2c uses plain-text community strings for authentication and lacks encryption, making it vulnerable to eavesdropping and data manipulation.
- Community strings sent in plain text
- No encryption for messages
- Vulnerable to sniffing and data tampering
- SNMPv3 addresses these issues with authentication and encryption
Memory trick: SNMPv2c: Open book, no lock.