Cisco SNMP agent can be instructed to shut down the RTT monitor service

Risk Level: Low risk vulnerability  Low

Check or Attack Name: SNMPCiscoRTTMONKill

Platforms: Cisco
Description:

This exploit attempts to reset the RTTMON Application using SNMP Set-PDU request of these parameters:

  • rttMonApplReset
  • rttMonApplPreConfigedReset

If successful, the RTT monitor application has likely been reset.

Remedy:

Set the community string to a value that is not easily guessed. Use uppercase, lowercase, and numeric characters.

References:

X-Force Logo
Know Your Risks