Check: RHEL-08-040190
RHEL 8 STIG:
RHEL-08-040190
(in versions v1 r14 through v1 r1)
Title
The Trivial File Transfer Protocol (TFTP) server package must not be installed if not required for RHEL 8 operational support. (Cat I impact)
Discussion
If TFTP is required for operational support (such as the transmission of router configurations) its use must be documented with the Information System Security Officer (ISSO), restricted to only authorized personnel, and have access control rules established.
Check Content
Verify a TFTP server has not been installed on the system with the following command: $ sudo yum list installed tftp-server tftp-server.x86_64 5.2-24.el8 If TFTP is installed and the requirement for TFTP is not documented with the ISSO, this is a finding.
Fix Text
Remove the TFTP package from the system with the following command: $ sudo yum remove tftp-server
Additional Identifiers
Rule ID: SV-230533r627750_rule
Vulnerability ID: V-230533
Group Title: SRG-OS-000480-GPOS-00227
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |