STIGQter STIGQter: STIG Summary: VMware vSphere 7.0 ESXi Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 02 Apr 2025:

Simple Network Management Protocol (SNMP) must be configured properly on the ESXi host.

DISA Rule

SV-256414r959010_rule

Vulnerability Number

V-256414

Group Title

SRG-OS-000480-VMM-002000

Rule Version

ESXI-70-000053

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

To disable SNMP from an ESXi shell, run the following command:

# esxcli system snmp set -e no

or

From a PowerCLI command prompt while connected to the ESXi Host:

Get-VMHostSnmp | Set-VMHostSnmp -Enabled $false

To configure SNMP for v3 targets, use the "esxcli system snmp set" command set locally on the host or remotely via PowerCLI.

Check Contents

From an ESXi shell, run the following command:

# esxcli system snmp get

or

From a PowerCLI command prompt while connected to the ESXi host, run the following command:

Get-VMHostSnmp | Select *

If SNMP is not in use and is enabled, this is a finding.

If SNMP is enabled and read-only communities are set to "public", this is a finding.

If SNMP is enabled and is not using v3 targets, this is a finding.

Note: SNMP v3 targets can only be viewed and configured via the "esxcli" command.

Vulnerability Number

V-256414

Documentable

False

Rule Version

ESXI-70-000053

Severity Override Guidance

From an ESXi shell, run the following command:

# esxcli system snmp get

or

From a PowerCLI command prompt while connected to the ESXi host, run the following command:

Get-VMHostSnmp | Select *

If SNMP is not in use and is enabled, this is a finding.

If SNMP is enabled and read-only communities are set to "public", this is a finding.

If SNMP is enabled and is not using v3 targets, this is a finding.

Note: SNMP v3 targets can only be viewed and configured via the "esxcli" command.

Check Content Reference

M

Target Key

5518