CCE-50210-4Platform: cpe:/o:apple:mac_os_14 | Date: (C)2023-11-28 (M)2023-11-28 |
The system _MUST_ be configured to enforce multifactor authentication.
All users _MUST_ go through multifactor authentication to prevent unauthenticated access and potential compromise to the system.
NOTE: /etc/pam.d/login will be automatically modified to its original state following any update or major upgrade to the operating system.
Setting the default value to "yes" will mess up services like SSH, if smart card authentication is not set up in the machine
Fix:
Add the following lines in /etc/pam.d/login file:
auth sufficient pam_smartcard.so
auth required pam_deny.so
Parameter:
[yes/no]
Technical Mechanism:
Add the following lines in /etc/pam.d/login file:
auth sufficient pam_smartcard.so
auth required pam_deny.so
CCSS Severity: | CCSS Metrics: |
CCSS Score : 8.1 | Attack Vector: NETWORK |
Exploit Score: 2.2 | Attack Complexity: HIGH |
Impact Score: 5.9 | Privileges Required: NONE |
Severity: HIGH | User Interaction: NONE |
Vector: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H | Scope: UNCHANGED |
| Confidentiality: HIGH |
| Integrity: HIGH |
| Availability: HIGH |
| |
References: Resource Id | Reference |
---|
SCAP Repo OVAL Definition | oval:org.secpod.oval:def:94777 |