Check: SRG-OS-000021-VMM-000050
Virtual Machine Manager SRG:
SRG-OS-000021-VMM-000050
(in versions v2 r2 through v1 r3)
Title
The VMM must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period. (Cat II impact)
Discussion
By limiting the number of failed login attempts, the risk of unauthorized VMM access via user password guessing, otherwise known as brute-forcing, is reduced. Limits are imposed by locking the account. This restriction may be relaxed for administrative accounts to avoid potential Denial of Service.
Check Content
Verify the VMM enforces the limit of three consecutive invalid logon attempts by a user during a 15-minute time period. If it does not, this is a finding.
Fix Text
Configure the VMM to enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period, by locking the account.
Additional Identifiers
Rule ID: SV-207342r958388_rule
Vulnerability ID: V-207342
Group Title: SRG-OS-000021
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000044 |
Enforce the organization-defined limit of consecutive invalid logon attempts by a user during the organization-defined time period. |
Controls
Number | Title |
---|---|
AC-7 |
Unsuccessful Logon Attempts |