Check: GEN000454
VMware ESX 3 Server:
GEN000454
(in version v1 r2)
Title
The system must display the number of unsuccessful login attempts since the last successful login for a user account upon logging in. (Cat III impact)
Discussion
Providing users with feedback on recent login failures facilitates user recognition and reporting of attempted unauthorized account use.
Check Content
Determine if the system displays the number of failed login attempts upon logging in. Attempt to log into the system once using an invalid password or other authenticator, then log into the system using the same account with a valid authenticator. If the system does not display a message indicating there was a failed login attempt, this is a finding.
Fix Text
Configure the system to display the number of failed logins upon logging in. Consult OS documentation for the necessary procedure.
Additional Identifiers
Rule ID: SV-25947r1_rule
Vulnerability ID: V-22300
Group Title: GEN000454
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000053 |
The information system notifies the user, upon successful logon/access, of the number of unsuccessful logon/access attempts since the last successful logon/access. |
Controls
Number | Title |
---|---|
AC-9 (1) |
Unsuccessful Logons |