Check: GEN003810
VMware ESX 3 Server:
GEN003810
(in version v1 r2)
Title
The portmap or rpcbind service must not be running unless needed. (Cat II impact)
Discussion
The portmap and rpcbind services increase the attack surface of the system and should only be used when needed. The portmap or rpcbind services are used by a variety of services using Remote Procedure Calls (RPCs).
Check Content
If the portmap service is required for system operations, this is not a finding. Determine if the portmap service is running. If so, this is a finding.
Fix Text
Disable the portmap service.
Additional Identifiers
Rule ID: SV-26093r1_rule
Vulnerability ID: V-22429
Group Title: GEN003810
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001436 |
The organization disables organization-defined networking protocols within the information system deemed to be nonsecure except for explicitly identified components in support of specific operational requirements. |
Controls
Number | Title |
---|---|
No controls are assigned to this check |