Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Notifications
Login / Register
Community
Community
Notifications
close
  • Forums
  • Knowledge Center
  • Events & Webinars
  • Ideas
  • Blogs
Help
Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Login / Register
Sustainability
Sustainability

Join our "Ask Me About" community webinar on May 20th at 9 AM CET and 5 PM CET to explore cybersecurity and monitoring for Data Center and edge IT. Learn about market trends, cutting-edge technologies, and best practices from industry experts.
Register and secure your Critical IT infrastructure

SNMP vulnerability in disaster recovery node

EcoStruxure IT forum

Schneider Electric support forum about installation and configuration for DCIM including EcoStruxure IT Expert, IT Advisor, Data Center Expert, and NetBotz

cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • Home
  • Schneider Electric Community
  • EcoStruxure IT
  • EcoStruxure IT forum
  • SNMP vulnerability in disaster recovery node
Options
  • Subscribe to RSS Feed
  • Mark Topic as New
  • Mark Topic as Read
  • Float this Topic for Current User
  • Bookmark
  • Subscribe
  • Mute
  • Printer Friendly Page
Invite a Co-worker
Send a co-worker an invite to the portal.Just enter their email address and we'll connect them to register. After joining, they will belong to the same company.
You have entered an invalid email address. Please re-enter the email address.
This co-worker has already been invited to the Exchange portal. Please invite another co-worker.
Please enter email address
Send Invite Cancel
Invitation Sent
Your invitation was sent.Thanks for sharing Exchange with your co-worker.
Send New Invite Close
Top Experts
User Count
Cory_McDonald
Admiral Cory_McDonald Admiral
124
Jef
Admiral Jef Admiral
108
gsterling
Captain gsterling Captain
71
APC_Steve
Captain APC_Steve Captain
62
View All

Invite a Colleague

Found this content useful? Share it with a Colleague!

Invite a Colleague Invite
Back to EcoStruxure IT forum
DCIM_Support
Picard DCIM_Support
Picard

Posted: ‎2020-07-05 07:48 PM . Last Modified: ‎2024-04-03 02:31 AM

0 Likes
7
1167
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2020-07-05 07:48 PM . Last Modified: ‎2024-04-03 02:31 AM

SNMP vulnerability in disaster recovery node

There have been a lot of discussions here about the default SNMPv1 community string but didn't find anything related to DCO Disaster recovery node (High Availability). The problem is that our security scanners are reporting a vulnerability since the DR seems to be using the default "public" even though we have disabled the SNMPv1 and in addition changed it from "public" to something else.

It seems that these configurations are not taken into use if the DR is not promoted to master? Scans were fine when the DR was the master but once dropped to being a DR, the same vulnerability was found.

(CID:144313595)

Labels
  • Labels:
  • Data Center Operation
Reply

Link copied. Please paste this link to share this article on your social media post.

  • All forum topics
  • Previous Topic
  • Next Topic
Replies 7
DCIM_Support
Picard DCIM_Support
Picard

Posted: ‎2020-07-05 07:48 PM . Last Modified: ‎2024-04-03 02:31 AM

0 Likes
5
1168
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2020-07-05 07:48 PM . Last Modified: ‎2024-04-03 02:31 AM

Hi Michael,

SNMP v1 can be disabled both on the master node and the DR node, if haven't tried it yet, please go to server (both master and DR) webmin interface,  StruxureWare DC Operation > Setup , un-check the v1 option for "Enable SNMP server", and then push the Setup button:

And then check your vulnerability scans to See if that helps, otherwise it would be great if I could have details about your scanning tool and its DCO related reports, thanks.

Kind regards

(CID:144313614)

Reply

Link copied. Please paste this link to share this article on your social media post.

DCIM_Support
Picard DCIM_Support
Picard

Posted: ‎2020-07-05 07:48 PM . Last Modified: ‎2024-04-03 02:31 AM

In response to DCIM_Support
0 Likes
0
1168
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2020-07-05 07:48 PM . Last Modified: ‎2024-04-03 02:31 AM

Hi Jef!

The SNMPv1 is disabled on both servers. Before disabling, we also changed the community from "public" to something else. Master node passes the scans with no problems, so does the DR if it's promoted to master. But when it is in "standby" as a DR, the scans report: "Default or Guessable SNMP community names: public". So it seems it uses some default values when working as a DR. I'll ask some more information from our IT Security.

(CID:144313625)

Reply

Link copied. Please paste this link to share this article on your social media post.

DCIM_Support
Picard DCIM_Support
Picard

Posted: ‎2020-07-05 07:48 PM . Last Modified: ‎2024-04-03 02:31 AM

In response to DCIM_Support
0 Likes
0
1168
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2020-07-05 07:48 PM . Last Modified: ‎2024-04-03 02:31 AM

Hi Michael,

Thanks for the info - I will send you an invite to my =S= box shortly so the data safely can be shared with me, thanks.

Kind regards

(CID:144313664)

Reply

Link copied. Please paste this link to share this article on your social media post.

DCIM_Support
Picard DCIM_Support
Picard

Posted: ‎2020-07-05 07:48 PM . Last Modified: ‎2024-04-03 02:31 AM

In response to DCIM_Support
0 Likes
0
1168
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2020-07-05 07:48 PM . Last Modified: ‎2024-04-03 02:31 AM

Hi Michael,

What is the version of your DCO servers?

Kind regards

(CID:144313851)

Reply

Link copied. Please paste this link to share this article on your social media post.

DCIM_Support
Picard DCIM_Support
Picard

Posted: ‎2020-07-05 07:48 PM . Last Modified: ‎2024-04-03 02:31 AM

In response to DCIM_Support
0 Likes
0
1167
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2020-07-05 07:48 PM . Last Modified: ‎2024-04-03 02:31 AM

Currently on 8.2.2.

(CID:144313859)

Reply

Link copied. Please paste this link to share this article on your social media post.

DCIM_Support
Picard DCIM_Support
Picard

Posted: ‎2020-07-05 07:48 PM . Last Modified: ‎2024-04-03 02:31 AM

In response to DCIM_Support
0 Likes
0
1167
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2020-07-05 07:48 PM . Last Modified: ‎2024-04-03 02:31 AM

Hi Michael,

I have had a setup (DCO+DR node) using the latest release version (DCO 8.3) that were running the last few days. This setup were included in our daily security scanning without any SNMP security notifications.

In general, it is recommended to update the product (DCO) to latest release version, which should also contain OS related updates.

Kind regards

(CID:144868637)

Reply

Link copied. Please paste this link to share this article on your social media post.

DCIM_Support
Picard DCIM_Support
Picard

Posted: ‎2020-07-05 07:49 PM . Last Modified: ‎2023-10-22 03:49 AM

0 Likes
0
1167
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Link copied. Please paste this link to share this article on your social media post.

Posted: ‎2020-07-05 07:49 PM . Last Modified: ‎2023-10-22 03:49 AM

superhero.png

This question is closed for comments. You're welcome to start a new topic if you have further comments on this issue.

Reply

Link copied. Please paste this link to share this article on your social media post.

To The Top!

Forums

  • APC UPS Data Center Backup Solutions
  • EcoStruxure IT
  • EcoStruxure Geo SCADA Expert
  • Metering & Power Quality
  • Schneider Electric Wiser

Knowledge Center

Events & webinars

Ideas

Blogs

Get Started

  • Ask the Community
  • Community Guidelines
  • Community User Guide
  • How-To & Best Practice
  • Experts Leaderboard
  • Contact Support
Brand-Logo
Subscribing is a smart move!
You can subscribe to this board after you log in or create your free account.
Forum-Icon

Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.

Register today for FREE

Register Now

Already have an account? Login

Terms & Conditions Privacy Notice Change your Cookie Settings © 2025 Schneider Electric

This is a heading

With achievable small steps, users progress and continually feel satisfaction in task accomplishment.

Usetiful Onboarding Checklist remembers the progress of every user, allowing them to take bite-sized journeys and continue where they left.

of