Cisco equipment can be used to send ICMP pings via SNMP |
---|
Risk Level: | Medium | Check or Attack Name: SNMPCiscoPingball |
---|---|---|
Platforms: | Cisco | |
Description: | Some Cisco routers can be configured to issue ICMP echo requests through the SNMP agent. This capability can be used to load other networked devices with echo response activity. As coded here, the router is the target for the ICMP echo. This condition results in no appreciable network traffic. If repeated many times, the ICMP echo activities starve the router's I/O and memory resources and causes the router to not respond to ICMP echo. |
|
Remedy: | Set the community string to a value that is not easily guessed. Use uppercase, lowercase, and numeric characters. The router should also apply access control to allow SNMP requests from known valid source sub-networks and authorized IP addresses. |
|
References: | Cisco Systems Product Overview, Simple Network Management Protocol (SNMP), http://www.cisco.com/warp/public/535/3.html |
Know Your Risks |