Check: GEN005520
VMware ESX 3 Server:
GEN005520
(in version v1 r2)
Title
The SSH client must be configured to not allow X11 forwarding. (Cat III impact)
Discussion
X11 forwarding over SSH allows for the secure remote execution of X11-based applications. This feature can increase the attack surface of an SSH connection and should not be enabled unless needed. If this function is necessary to support a valid mission requirement, its use must be authorized and approved in the system accreditation package.
Check Content
Check the SSH client configuration for the X11 forwarding setting. # grep -i ForwardX11 /etc/ssh/ssh_config | grep -v '^#' If no lines are returned, or the returned setting has a value evaluating to yes, this is a finding.
Fix Text
Edit the SSH client configuration and change or add the ForwardX11 setting to no.
Additional Identifiers
Rule ID: SV-26762r1_rule
Vulnerability ID: V-22469
Group Title: GEN005520
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000221 |
The information system enforces security policies regarding information on interconnected systems. |
Controls
Number | Title |
---|---|
No controls are assigned to this check |