10. Security Considerations
There are a number of management objects defined in this document that have a MAX-ACCESS clause of read-write and/or read-create. Such objects may be considered sensitive or vulnerable in some network environments. The support for setting and/or changing these objects in a non-secure environment without proper protection can have a negative effect on network operations. These are the tables and objects and their sensitivity/vulnerability:
- The ability to change the snmpTargetAddrTable and snmpTargetParamsTable allows the configuration of the targets of SNMP messages. This allows the creation of management targets which may result in the sending of SNMP messages to a different transport address. If such a target is maliciously configured, it could be used to generate SNMP messages to a different address, possibly with a different security level. This could potentially be used to cause SNMP messages to be sent to an unintended recipient.
- The snmpTargetParamsTable also allows the configuration of a securityName and securityLevel to be used when generating messages. Malicious changes to this table could cause messages to be sent with a higher or lower security level than intended, possibly allowing the messages to be intercepted or modified.
- The snmpNotifyTable is used to configure which targets receive notifications. Malicious changes to this table could cause notifications to be sent to unintended recipients, or could prevent notifications from being sent to intended recipients.
- The snmpNotifyFilterProfileTable and snmpNotifyFilterTable are used to configure filters for notifications. Malicious changes to these tables could cause notifications to be incorrectly filtered, preventing them from being sent to intended recipients, or could cause them to be sent to unintended recipients.
It is recommended that these objects be properly protected using the access control mechanisms defined in [RFC3411]. It is also recommended that the securityName and securityLevel for each target be configured to require authentication and/or privacy, as appropriate for the environment.
SNMPv1 and SNMPv2C are not secure, and the use of these security models for the generation of notifications is not recommended. If the SNMPv1 or SNMPv2C security models are used, it is possible that the notifications might be intercepted or modified.