IT Mandate: Disable SNMP on ControlLogix processors

TConnolly

Lifetime Supporting Member
Join Date
Apr 2005
Location
Salt Lake City
Posts
6,152
I got the following request from IT as a result of a vulnerability scan they performed.

Issue: SNMP Service

Solution: Disable the SNMP service on the remote host if you do not use it, filter incoming UDP packets going to this port, or change the default community string.


Then they gave me a list of IP addresses, all of which are for ControlLogix 1756-ENBT/A or 1756-ENBT/B modules and one CompactLogix L35E. None of the 1756-EN2T modules are affected.





I can't see anything even remotely resembling SNMP service settings in the module configuration tools - any suggestions?
 
I went through a lot of fire-drills on this issue almost a decade ago:

http://www.cert.org/advisories/CA-2002-03.html

The simple answer is that there's no risk in SNMP with these devices; since they are not IP network gateways there's no ability for an attacker to bridge through them.

If you need to change the default passwords, there's a good RA technote that describes using the common utility GETIF to change the various community passwords.

http://rockwellautomation.custhelp.com/app/answers/detail/a_id/34413

I don't think SNMP can be disabled on these modules.

The right way to approach these issues is what it sounds like they're doing: good perimeter defenses, baseline understanding of interior network requirements, and vigilant monitoring.
 

Similar Topics

Hello, I am still new to PLC programming and I just got this job two year out of school so I don’t remember much. I was given a task were I have...
Replies
1
Views
166
How can we disable the DHCP server on a Stratix 5700 ethernet switch? It is running on a machine with Rockwell automation and drives. We...
Replies
6
Views
1,580
Hello. We have a Powerflex 700s phase II firmware 4.002, but the encoder card is burned. We want to disable it to use the Drive without motion...
Replies
0
Views
454
As above. I've been fishing around on TIA portal but haven't found a "Disable channel" tickbox. Is there one? If so, where is it? Cheers
Replies
9
Views
1,327
Hello, I have plc Schneider TM241CE40T with the hmi HMIS5T. Do you have idea how to disable a button after an emergency stop to vijeo designer ...
Replies
5
Views
1,445
Back
Top Bottom