Check: MFD02.005
Multifunction Device and Network Printers STIG:
MFD02.005
(in versions v2 r14 through v2 r9)
Title
There is no restriction on where a MFD or a printer can be remotely managed. (Cat I impact)
Discussion
Since unrestricted access to the MFD or printer for management is not required the restricting the management interface to specific IP addresses decreases the exposure of the system to malicious actions. If the MFD or printer is compromised it could lead to a denial of service or a compromise of sensitive data. The SA will ensure devices can only be remotely managed by SA’s or printer administrators from specific IPs (SA workstations and print spooler).
Check Content
The reviewer will, with the assistance of the SA, verify that the MFD or printer can only be remotely managed by SA or printer administrator from specific IPs (SA workstations and print spooler). Look for list that restricts the protocol used for administrative access to specific IP addresses.
Fix Text
Restrict access to the MFD's or printer's management function to a specific set of IP addresses. If the device lacks this functionality use an ACL in a router, firewall or switch to restrict the access.
Additional Identifiers
Rule ID: SV-7009r1_rule
Vulnerability ID: V-6784
Group Title: MFD or a printer can be managed from any IP
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002415 |
The organization employs boundary protection mechanisms to separate organization-defined information system components supporting organization-defined missions and/or business functions. |
Controls
Number | Title |
---|---|
SC-7 (21) |
Isolation Of Information System Components |