Check: WIR-MOS-AND-040-02
Android 2.2 (Dell) STIG:
WIR-MOS-AND-040-02
(in version v1 r2)
Title
All mobile operating system (OS) device Bluetooth radio profiles must be disabled except for the serial port, handset and headset profiles. (Cat II impact)
Discussion
The Bluetooth radio can be used by a hacker to connect to the smartphone without the knowledge of the user. Sensitive DoD data could be exposed and the hacker could use the device to attack the enclave. The serial port profile is used by the DoD approved Bluetooth smart card reader and the headset and handset profiles are used by the DoD approved Bluetooth headset.
Check Content
The Bluetooth Security Monitor application is used to only allow the three approved Bluetooth profiles: serial port, handset, headset. (In late 2011, this configuration setting will be available in the Good server console.) Verify the Bluetooth Security Monitor application has been installed on the mobile OS device. -Have the system administrator show that Setup.apk is in the list of installed applications on the device (Settings>Applications>Manage applications>All). Mark as a finding if the required file is not installed.
Fix Text
Install the required Bluetooth configuration application.
Additional Identifiers
Rule ID: SV-38756r1_rule
Vulnerability ID: V-29524
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |