STIGQter STIGQter: STIG Summary: VMware vSphere 6.7 VAMI-lighttpd Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 09 Mar 2021:

VAMI server binaries and libraries must be verified for their integrity.

DISA Rule

SV-239723r679279_rule

Vulnerability Number

V-239723

Group Title

SRG-APP-000131-WSR-000051

Rule Version

VCLD-67-000015

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If the VAMI binaries have been modified from the default state when deployed as part of the VCSA, the system must be wiped and redeployed or restored from backup.

VMware does not recommend or support recovering from such a state by reinstalling RPMs or similar efforts.

Check Contents

At the command prompt, execute the following command:

# rpm -qa|grep lighttpd|xargs rpm -V|grep -v "lighttpd.conf"

If the command returns any output, this is a finding.

Vulnerability Number

V-239723

Documentable

False

Rule Version

VCLD-67-000015

Severity Override Guidance

At the command prompt, execute the following command:

# rpm -qa|grep lighttpd|xargs rpm -V|grep -v "lighttpd.conf"

If the command returns any output, this is a finding.

Check Content Reference

M

Target Key

5335

Comments