Security
How to find devices using default or version 1 and 2c SNMP communities
An SNMP community string is a password sent in clear text, and versions 1 and 2c have no other protection. Communities named public and private are worse still, because they are the first two anyone tries. This usually survives not through carelessness but through inheritance: a monitoring system needed read access years ago, the community was set fleet-wide, and nothing since has had a reason to revisit it.
Before you start
What you need
- Module required: compliance.
- Permission required: view_audit.
- All benchmarked platforms; the wording of the check differs by vendor
1. Open a device and read its SNMP checks

2. Filter to the failing checks

3. Separate the two findings

The limits
What this view does not tell you
- A device with no SNMP configured at all passes both checks. Passing therefore means "not exposed this way", not "monitored securely" - the benchmark cannot tell an intentionally hardened device from one nobody ever set up.
- Community strings are credentials. NacTrack reports that a weak one exists and does not print its value in the evidence, so the report can be shared without leaking what it found.
