Check: GEN005530
VMware ESX 3 Server:
GEN005530
(in version v1 r2)
Title
The SSH daemon must not permit user environment settings. (Cat III impact)
Discussion
SSH may be used to provide limited functions other than an interactive shell session, such as file transfer. If local, user-defined environment settings (such as, those configured in ~/.ssh/authorized_keys and ~/.ssh/environment) are configured by the user and permitted by the SSH daemon, they could be used to alter the behavior of the limited functions, potentially granting unauthorized access to the system.
Check Content
Check the PermitUserEnvironment setting in the SSH daemon configuration. Procedure: # grep -i PermitUserEnvironment sshd_config If the setting is not present or set to a value other than no, this is a finding.
Fix Text
Edit the SSH daemon configuration and edit (or add) the PermitUserEnvironment setting with a value of no.
Additional Identifiers
Rule ID: SV-26773r1_rule
Vulnerability ID: V-22479
Group Title: GEN005530
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000221 |
The information system enforces security policies regarding information on interconnected systems. |
Controls
Number | Title |
---|---|
No controls are assigned to this check |