Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Notifications
Login / Register
Community
Community
Notifications
close
  • Forums
  • Knowledge Center
  • Events & Webinars
  • Ideas
  • Blogs
Help
Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Login / Register
Sustainability
Sustainability

Launch of Consumer/Home Owner registration process!
We are pleased to announce the commencement of the Consumer/Home Owner Registration Process on Community. Consumers/Home Owners may now proceed to register by clicking on Login/Register. The process is straightforward and designed to be completed in just a few steps.

DCE/DCO and "writable snmp vulnerability"

EcoStruxure IT forum

Schneider Electric support forum about installation and configuration for DCIM including EcoStruxure IT Expert, IT Advisor, Data Center Expert, and NetBotz

Search in

Improve your search experience:

  • Exact phrase โ†’ Use quotes " " (e.g., "error 404")
  • Wildcard โ†’ Use * for partial words (e.g., build*, *tion)
  • AND / OR โ†’ Combine keywords (e.g., login AND error, login OR signโ€‘in)
  • Keep it short โ†’ Use 2โ€“3 relevant words , not full sentences
  • Filters โ†’ Narrow results by section (Knowledge Base, Users, Products)
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results forย 
Showย ย onlyย  | Search instead forย 
Did you mean:ย 
  • Home
  • Schneider Electric Community
  • EcoStruxure IT
  • EcoStruxure IT forum
  • DCE/DCO and "writable snmp vulnerability"
Options
  • Mark Topic as New
  • Mark Topic as Read
  • Float this Topic for Current User
  • Bookmark
  • Subscribe
  • Mute
  • Printer Friendly Page
Invite a Co-worker
Send a co-worker an invite to the portal.Just enter their email address and we'll connect them to register. After joining, they will belong to the same company.
You have entered an invalid email address. Please re-enter the email address.
This co-worker has already been invited to the Exchange portal. Please invite another co-worker.
Please enter email address
Send Invite Cancel
Invitation Sent
Your invitation was sent.Thanks for sharing Exchange with your co-worker.
Send New Invite Close
Top Experts
User Count
Cory_McDonald
Admiral Cory_McDonald Admiral
125
Jef
Admiral Jef Admiral
111
gsterling
Captain gsterling Captain
71
APC_Steve
Captain APC_Steve Captain
65
View All

Invite a Colleague

Found this content useful? Share it with a Colleague!

Invite a Colleague Invite
Back to EcoStruxure IT forum
Start a Topic
Anonymous user
Not applicable

Posted: โ€Ž2022-01-19 12:46 AM

0 Likes
8
1866
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: โ€Ž2022-01-19 12:46 AM

DCE/DCO and "writable snmp vulnerability"

Hello!

 

During recent Vulnerability Assessment scan, a "writable SNMP community" vulnerability was discovered within DCE/DCO.

I can see option to change default name for writable SNMP community, but I don't see an option to disable it completely or set password for it.

Can you advise how to protect it/remediate it?

Labels
  • Labels:
  • Data Center Expert
  • Data Center Operation
  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

  • All forum topics
  • Previous Topic
  • Next Topic
Replies 8
Jef
Admiral Jef Admiral
Admiral

Posted: โ€Ž2022-01-19 01:11 AM

0 Likes
0
1860
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: โ€Ž2022-01-19 01:11 AM

Hi Przemyslaw,

 

I will answer for DCO/ITA, you can configure it via the server webmin interface.

For DCO:
https://<DCO server IP>:10000
StruxureWare DC Operation > Setup

For ITA:
https://<ITA server IP>:10000
EcoStruxure IT Advisor > Setup

 

where you can enable or disable SNMP options (v1 and v3) and/or set password.

SNMP v1 is disabled by default in latest versions of ITA.

 

Kind regards,

Jef

 

  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

APC_Steve
Captain APC_Steve Captain
Captain

Posted: โ€Ž2022-01-19 02:13 AM . Last Modified: โ€Ž2022-01-19 02:14 AM

0 Likes
6
1854
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: โ€Ž2022-01-19 02:13 AM . Last Modified: โ€Ž2022-01-19 02:14 AM

Hi @Anonymous user ,

 

To disable SNMP read/write on DCE, simply uncheck "Enable" on the following page (it is disabled by default):

disable.PNG

There is only SNMP version 1 so there is no password option. There are only community names.

You do not have the option to enable or disable read/write individually. You get both read/write, or you get neither.

 

Thanks,

Steve

  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

silvia_scv
Crewman silvia_scv
Crewman

Posted: โ€Ž2022-01-19 05:04 AM

In response to APC_Steve
0 Likes
5
1843
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: โ€Ž2022-01-19 05:04 AM

Hi Steve,

 

having disabled SNMP in DCE server I now get the alarm you can see in attachment. In the DCO though in external system config it's still in ok status and it passes the test. I saw an old conversation on this topic Solved: snmp vunerability - Communities (se.com) and I see indeed in my DCE the DCE server itself is found as an item. What can I do in this case to still keep SNMP disabled but have DCO and DCE communicating?

 

Thank you in advance

 

Silvia

Attachments
  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

APC_Steve
Captain APC_Steve Captain
Captain

Posted: โ€Ž2022-01-19 05:43 AM

In response to silvia_scv
0 Likes
4
1839
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: โ€Ž2022-01-19 05:43 AM

hi @silvia_scv 

 

That would seem to indicate that "usdcepal01.internal...." is the server itself and that it is being monitored via SNMP. As I mentioned, you have the option to enable SNMP or disable it. If you disable it, you will obviously not be able to monitor it using SNMP. You have to make the choice, enabled or disabled.

 

If enabled, all I can suggest for higher security is that you use a more complex write community string and don't give it out but if it being enabled at all is the issue, you're back to the choice of enabled or disabled.

 

Steve

  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

Anonymous user
Not applicable

Posted: โ€Ž2022-01-19 05:45 AM

In response to APC_Steve
0 Likes
3
1836
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: โ€Ž2022-01-19 05:45 AM

Steve, how can we check if the device is monitored by SNMP or how to change it to some other monitoring method?

In the properties of the server, there is nothing clearly visible that would indicate SNMP monitoring ๐Ÿ˜ž

 

  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

APC_Steve
Captain APC_Steve Captain
Captain

Posted: โ€Ž2022-01-19 06:13 AM

In response to Anonymous user
0 Likes
2
1828
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: โ€Ž2022-01-19 06:13 AM

Hi @Anonymous user 

 

There is no other alternative in DCE to monitor another (or the same) DCE server other than SNMP. Your device discovery options in DCE are SNMP, Modbus (which we don't do to monitor the server) and NetBotz which can't be used to monitor the server.

You also disabled SNMP and stated that you lost com at that point so with all of this info, it's pretty obvious that this was how you were monitoring it.

 

Again, your options are to enable SNMP and allow it to be monitored or disable it and don't monitor it. There's very little info available via SNMP so you're not losing that much. To see what you have set up in DCE to monitor any system using SNMP is to go to the device menu --> SNMP Device Communications Settings --> Device Scan Settings and look for the IP or hostname of the server. Check it and click edit device settings to see the configuration.

 

Thanks,

Steve

 

 

 

 

  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

Anonymous user
Not applicable

Posted: โ€Ž2022-01-19 06:19 AM

In response to APC_Steve
0 Likes
1
1826
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: โ€Ž2022-01-19 06:19 AM

Thank you very much, it's all clear now.

If we would like to keep SNMP running, is there any possibility to enable some DCE firewalling or within Struxureware, which would limit the SNMP communication just internally and disable all external connectivity?

 

  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

APC_Steve
Captain APC_Steve Captain
Captain

Posted: โ€Ž2022-01-19 06:37 AM

In response to Anonymous user
0 Likes
0
1822
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: โ€Ž2022-01-19 06:37 AM

hi @Anonymous user 

 

Sorry but no, the options for SNMP are as you see them on the previous page that I sent as a screenshot. There is no way to set only a specific IP / system to monitor DCE. There is no way to keep it internal to the system. 

 

Steve

  • Tags:
  • english
Reply

Link copied. Please paste this link to share this article on your social media post.

Preview Exit Preview

never-displayed

You must be signed in to add attachments

never-displayed

ย 

Youโ€™ve reached the end of your document

WHATโ€™S NEXT?

Ask our Experts

Didn't find what you are looking for? Ask our experts!

My Dashboard

Check out the new Feeds and activities that are relevant to you.

To The Top!

Forums

  • APC UPS Data Center Backup Solutions
  • EcoStruxure IT
  • EcoStruxure Geo SCADA Expert
  • Metering & Power Quality
  • Schneider Electric Wiser

Knowledge Center

Events & webinars

Ideas

Blogs

Get Started

  • Ask the Community
  • Community Guidelines
  • Community User Guide
  • How-To & Best Practice
  • Experts Leaderboard
  • Contact Support
Brand-Logo
Subscribing is a smart move!
You can subscribe to this board after you log in or create your free account.
Forum-Icon

Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.

Register today for FREE

Register Now

Already have an account? Login

Terms & Conditions Privacy Notice Change your Cookie Settings ยฉ 2025 Schneider Electric

Welcome!

Welcome to your new personalized space.

of

Explore