Check: AIX7-00-003135
IBM AIX 7.x STIG:
AIX7-00-003135
(in versions v3 r1 through v1 r1)
Title
AIX must not respond to ICMPv6 echo requests sent to a broadcast address. (Cat II impact)
Discussion
Responding to broadcast ICMP echo requests facilitates network mapping and provides a vector for amplification attacks.
Check Content
From the command prompt, run the following command: # /usr/sbin/no -o bcastping bcastping = 0 If the value returned is not "0", this is a finding.
Fix Text
Configure the system to not respond to IPv6 multicast ICMP ECHO_REQUESTs by running: # /usr/sbin/no -p -o bcastping=0
Additional Identifiers
Rule ID: SV-215430r991589_rule
Vulnerability ID: V-215430
Group Title: SRG-OS-000480-GPOS-00227
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
CCI-000366 |
Implement the security configuration settings. |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
CM-6 |
Configuration Settings |