Re: [c-nsp] Blocking SNMPv3 engine-id discovery [was: Re: How to disable ILMI/SNMP CSCvs33325]

Nathan Lannine via cisco-nsp <[email protected]>
Newsgroups gmane.network.nsp.cisco
Message-ID <CABLvZbFZD17sgEqbjZ5AX2teQD-pYy8xNK253gcunTMsntOt+g@mail.gmail.com>
On Wed, Sep 21, 2022 at 6:52 AM Simon Leinen via cisco-nsp <
[email protected]> wrote:

> Gert Doering writes:
> > On Wed, Sep 21, 2022 at 08:14:30AM +0300, Hank Nussbacher wrote:
> >> Indeed the SNMP leaks appear to be exactly CSCtw74132 which we did
> >> not know about nor did Cisco TAC :-(
>

Just wanted to say thanks to you all for this thread.  Gave me a starting
point for mitigating this following a recent vuln scan result.  My biggest
challenge though was figuring out how to validate a fix, which, turns out,
can be ascertained by a packet capture while running "snmpget -v3 <host>"
or by running nmap against it with the nmap snmp-info script.

Regards!

_N
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.