Check: SRG-NET-000273-ALG-000129
Application Layer Gateway SRG:
SRG-NET-000273-ALG-000129
(in versions v2 r2 through v1 r2)
Title
The ALG must generate error messages that provide the information necessary for corrective actions without revealing information that could be exploited by adversaries. (Cat II impact)
Discussion
Providing too much information in error messages risks compromising the data and security of the application and system. Organizations carefully consider the structure/content of error messages. The required information within error messages will vary based on the protocol and error condition. Information that could be exploited by adversaries includes, for example, ICMP messages that reveal the use of firewalls or access-control lists.
Check Content
Verify the ALG generates error messages that provide the information necessary for corrective actions without revealing information that could be exploited by adversaries. If the ALG does not generate error messages that provide the information necessary for corrective actions without revealing information that could be exploited by adversaries, this is a finding.
Fix Text
Configure the ALG to generate error messages that provide the information necessary for corrective actions without revealing information that could be exploited by adversaries.
Additional Identifiers
Rule ID: SV-204969r396042_rule
Vulnerability ID: V-204969
Group Title: SRG-NET-000273
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001312 |
Generate error messages that provide information necessary for corrective actions without revealing information that could be exploited. |
Controls
Number | Title |
---|---|
SI-11 |
Error Handling |