The Photon operating system must use OpenSSH for remote maintenance sessions.
DISA Rule
SV-239139r675225_rule
Vulnerability Number
V-239139
Group Title
SRG-OS-000395-GPOS-00175
Rule Version
PHTN-67-000068
Severity
CAT II
CCI(s)
- CCI-000197 - The information system, for password-based authentication, transmits only cryptographically-protected passwords.
- CCI-000803 - The information system implements mechanisms for authentication to a cryptographic module that meet the requirements of applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance for such authentication.
- CCI-000877 - The organization employs strong authenticators in the establishment of nonlocal maintenance and diagnostic sessions.
- CCI-001941 - The information system implements replay-resistant authentication mechanisms for network access to privileged accounts.
- CCI-001942 - The information system implements replay-resistant authentication mechanisms for network access to non-privileged accounts.
- CCI-002420 - The information system maintains the confidentiality and/or integrity of information during preparation for transmission.
- CCI-002422 - The information system maintains the confidentiality and/or integrity of information during reception.
- CCI-002891 - The information system implements remote disconnect verification at the termination of nonlocal maintenance and diagnostic sessions.
Weight
10
Fix Recommendation
Installing openssh manually is not supported by VMware. Revert to a previous backup or redeploy the VCSA.
Check Contents
At the command line, execute the following command:
# rpm -qa|grep openssh
If there is no output, this is a finding.
Vulnerability Number
V-239139
Documentable
False
Rule Version
PHTN-67-000068
Severity Override Guidance
At the command line, execute the following command:
# rpm -qa|grep openssh
If there is no output, this is a finding.
Check Content Reference
M
Target Key
5323
Comments