Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Notifications
Login / Register
Community
Community
Notifications
close
  • Forums
  • Knowledge Center
  • Events & Webinars
  • Ideas
  • Blogs
Help
Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Login / Register
Sustainability
Sustainability

We Value Your Feedback!
Could you please spare a few minutes to share your thoughts on Cloud Connected vs On-Premise Services. Your feedback can help us shape the future of services.
Learn more about the survey or Click here to Launch the survey
Schneider Electric Services Innovation Team!

DCE/DCO and "writable snmp vulnerability"

EcoStruxure IT forum

Schneider Electric support forum about installation and configuration for DCIM including EcoStruxure IT Expert, IT Advisor, Data Center Expert, and NetBotz

cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • Home
  • Schneider Electric Community
  • EcoStruxure IT
  • EcoStruxure IT forum
  • DCE/DCO and "writable snmp vulnerability"
Options
  • Mark Topic as New
  • Mark Topic as Read
  • Float this Topic for Current User
  • Bookmark
  • Subscribe
  • Mute
  • Printer Friendly Page
Invite a Co-worker
Send a co-worker an invite to the portal.Just enter their email address and we'll connect them to register. After joining, they will belong to the same company.
You have entered an invalid email address. Please re-enter the email address.
This co-worker has already been invited to the Exchange portal. Please invite another co-worker.
Please enter email address
Send Invite Cancel
Invitation Sent
Your invitation was sent.Thanks for sharing Exchange with your co-worker.
Send New Invite Close
Top Experts
User Count
Cory_McDonald
Admiral Cory_McDonald Admiral
124
Jef
Admiral Jef Admiral
110
gsterling
Captain gsterling Captain
71
APC_Steve
Captain APC_Steve Captain
63
View All

Invite a Colleague

Found this content useful? Share it with a Colleague!

Invite a Colleague Invite
Back to EcoStruxure IT forum
salciu
Crewman salciu
Crewman

Posted: ‎2022-01-19 12:46 AM

0 Likes
8
1689
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2022-01-19 12:46 AM

DCE/DCO and "writable snmp vulnerability"

Hello!

 

During recent Vulnerability Assessment scan, a "writable SNMP community" vulnerability was discovered within DCE/DCO.

I can see option to change default name for writable SNMP community, but I don't see an option to disable it completely or set password for it.

Can you advise how to protect it/remediate it?

Labels
  • Labels:
  • Data Center Expert
  • Data Center Operation
  • Tags:
  • english
Reply
Contact Support

Link copied. Please paste this link to share this article on your social media post.

  • All forum topics
  • Previous Topic
  • Next Topic
Replies 8
Jef
Admiral Jef Admiral
Admiral

Posted: ‎2022-01-19 01:11 AM

0 Likes
0
1683
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2022-01-19 01:11 AM

Hi Przemyslaw,

 

I will answer for DCO/ITA, you can configure it via the server webmin interface.

For DCO:
https://<DCO server IP>:10000
StruxureWare DC Operation > Setup

For ITA:
https://<ITA server IP>:10000
EcoStruxure IT Advisor > Setup

 

where you can enable or disable SNMP options (v1 and v3) and/or set password.

SNMP v1 is disabled by default in latest versions of ITA.

 

Kind regards,

Jef

 

  • Tags:
  • english
Reply
Contact Support

Link copied. Please paste this link to share this article on your social media post.

APC_Steve
Captain APC_Steve Captain
Captain

Posted: ‎2022-01-19 02:13 AM . Last Modified: ‎2022-01-19 02:14 AM

0 Likes
6
1677
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2022-01-19 02:13 AM . Last Modified: ‎2022-01-19 02:14 AM

Hi @salciu ,

 

To disable SNMP read/write on DCE, simply uncheck "Enable" on the following page (it is disabled by default):

disable.PNG

There is only SNMP version 1 so there is no password option. There are only community names.

You do not have the option to enable or disable read/write individually. You get both read/write, or you get neither.

 

Thanks,

Steve

  • Tags:
  • english
Reply
Contact Support

Link copied. Please paste this link to share this article on your social media post.

silvia_scv
Crewman silvia_scv
Crewman

Posted: ‎2022-01-19 05:04 AM

In response to APC_Steve
0 Likes
5
1666
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2022-01-19 05:04 AM

Hi Steve,

 

having disabled SNMP in DCE server I now get the alarm you can see in attachment. In the DCO though in external system config it's still in ok status and it passes the test. I saw an old conversation on this topic Solved: snmp vunerability - Communities (se.com) and I see indeed in my DCE the DCE server itself is found as an item. What can I do in this case to still keep SNMP disabled but have DCO and DCE communicating?

 

Thank you in advance

 

Silvia

Attachments
  • Tags:
  • english
Reply
Contact Support

Link copied. Please paste this link to share this article on your social media post.

APC_Steve
Captain APC_Steve Captain
Captain

Posted: ‎2022-01-19 05:43 AM

In response to silvia_scv
0 Likes
4
1662
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2022-01-19 05:43 AM

hi @silvia_scv 

 

That would seem to indicate that "usdcepal01.internal...." is the server itself and that it is being monitored via SNMP. As I mentioned, you have the option to enable SNMP or disable it. If you disable it, you will obviously not be able to monitor it using SNMP. You have to make the choice, enabled or disabled.

 

If enabled, all I can suggest for higher security is that you use a more complex write community string and don't give it out but if it being enabled at all is the issue, you're back to the choice of enabled or disabled.

 

Steve

  • Tags:
  • english
Reply
Contact Support

Link copied. Please paste this link to share this article on your social media post.

salciu
Crewman salciu
Crewman

Posted: ‎2022-01-19 05:45 AM

In response to APC_Steve
0 Likes
3
1659
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2022-01-19 05:45 AM

Steve, how can we check if the device is monitored by SNMP or how to change it to some other monitoring method?

In the properties of the server, there is nothing clearly visible that would indicate SNMP monitoring 😞

 

  • Tags:
  • english
Reply
Contact Support

Link copied. Please paste this link to share this article on your social media post.

APC_Steve
Captain APC_Steve Captain
Captain

Posted: ‎2022-01-19 06:13 AM

In response to salciu
0 Likes
2
1651
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2022-01-19 06:13 AM

Hi @salciu 

 

There is no other alternative in DCE to monitor another (or the same) DCE server other than SNMP. Your device discovery options in DCE are SNMP, Modbus (which we don't do to monitor the server) and NetBotz which can't be used to monitor the server.

You also disabled SNMP and stated that you lost com at that point so with all of this info, it's pretty obvious that this was how you were monitoring it.

 

Again, your options are to enable SNMP and allow it to be monitored or disable it and don't monitor it. There's very little info available via SNMP so you're not losing that much. To see what you have set up in DCE to monitor any system using SNMP is to go to the device menu --> SNMP Device Communications Settings --> Device Scan Settings and look for the IP or hostname of the server. Check it and click edit device settings to see the configuration.

 

Thanks,

Steve

 

 

 

 

  • Tags:
  • english
Reply
Contact Support

Link copied. Please paste this link to share this article on your social media post.

salciu
Crewman salciu
Crewman

Posted: ‎2022-01-19 06:19 AM

In response to APC_Steve
0 Likes
1
1649
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2022-01-19 06:19 AM

Thank you very much, it's all clear now.

If we would like to keep SNMP running, is there any possibility to enable some DCE firewalling or within Struxureware, which would limit the SNMP communication just internally and disable all external connectivity?

 

  • Tags:
  • english
Reply
Contact Support

Link copied. Please paste this link to share this article on your social media post.

APC_Steve
Captain APC_Steve Captain
Captain

Posted: ‎2022-01-19 06:37 AM

In response to salciu
0 Likes
0
1645
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2022-01-19 06:37 AM

hi @salciu 

 

Sorry but no, the options for SNMP are as you see them on the previous page that I sent as a screenshot. There is no way to set only a specific IP / system to monitor DCE. There is no way to keep it internal to the system. 

 

Steve

  • Tags:
  • english
Reply
Contact Support

Link copied. Please paste this link to share this article on your social media post.

Preview Exit Preview

never-displayed

You must be signed in to add attachments

never-displayed

 
To The Top!

Forums

  • APC UPS Data Center Backup Solutions
  • EcoStruxure IT
  • EcoStruxure Geo SCADA Expert
  • Metering & Power Quality
  • Schneider Electric Wiser

Knowledge Center

Events & webinars

Ideas

Blogs

Get Started

  • Ask the Community
  • Community Guidelines
  • Community User Guide
  • How-To & Best Practice
  • Experts Leaderboard
  • Contact Support
Brand-Logo
Subscribing is a smart move!
You can subscribe to this board after you log in or create your free account.
Forum-Icon

Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.

Register today for FREE

Register Now

Already have an account? Login

Terms & Conditions Privacy Notice Change your Cookie Settings © 2025 Schneider Electric

This is a heading

With achievable small steps, users progress and continually feel satisfaction in task accomplishment.

Usetiful Onboarding Checklist remembers the progress of every user, allowing them to take bite-sized journeys and continue where they left.

of