Why does runZero attempt to authenticate with SNMP devices?

Modified on Fri, Sep 22, 2023 at 12:58 PM

There are a number of SNMPv1/v2 community strings that are well-known; the two most common are "public" and "private". Devices tend to be preconfigured to respond to one or both of these, which can be a security issue.

By default the runZero explorer will attempt to scan SNMP ports using these well-known community strings, to obtain data for fingerprinting, and also so that it can flag that the device responded to a well-known value by setting the snmp.defaultCommunities attribute.

You can override this behavior in the snmp-comms section of the Probes and SNMP section of the scan configuration.

You can read more about runZero's SNMP support at https://www.runzero.com/docs/snmp/

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article