Check: MFD02.002
Multifunction Device and Network Printers STIG:
MFD02.002
(in versions v2 r14 through v2 r13)
Title
The MFD or Network Printer must maintain configuration state (e.g., passwords, service settings) after a power down or restart. (Cat I impact)
Discussion
If the MFD does not maintain it state over a power down or restart, it will expose the network to all of the vulnerabilities that where mitigated by the modifications made to its configuration state. This also prevents accidental implementation of a “call-home” feature that is not allowed.
Check Content
The reviewer will verify the MFD or Network Printer maintains its configuration state after a power down or restart. Review the device documentation and/or confirm through demonstration to verify the MFD maintains configuration settings. If the MFD or Network Printer does not maintain its configuration state, this is a finding.
Fix Text
If the MFD or Network Printer cannot be configured to maintain state, then replace the MFD with a MFD that will maintain its configuration state (passwords, service settings, etc) after a power down or restart.
Additional Identifiers
Rule ID: SV-7004r2_rule
Vulnerability ID: V-6782
Group Title: MFD Configuration State After Power Down or Reboot
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001190 |
The information system fails to an organization-defined known-state for organization-defined types of failures. |
Controls
Number | Title |
---|---|
SC-24 |
Fail In Known State |