Check: VCENTER-000021
VMware vCenter Server Version 5 STIG:
VCENTER-000021
(in versions v2 r1 through v1 r7)
Title
The use of Linux-based clients must be restricted. (Cat III impact)
Discussion
Although SSL-based encryption is used to protect communication between client components and vCenter Server or ESXi, the Linux versions of these components do not perform certificate validation. Even if the self-signed certificates are replaced on vCenter and ESXi with legitimate certificates signed by the local root certificate authority or a third party, communications with Linux clients are still vulnerable to MiTM attacks.
Check Content
Verify all client operating systems connecting to the vCenter Server are not Linux. If any client operating system connecting to the vCenter Server is Linux-based, this is a finding.
Fix Text
Replace all Linux-based clients connecting to the vCenter Server with non-Linux-based clients.
Additional Identifiers
Rule ID: SV-250740r799910_rule
Vulnerability ID: V-250740
Group Title: SRG-APP-000516
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |