[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256040

 
 

909

 
 

199103

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-85312-7

Platform: cpe:/o:apple:mac_os_11Date: (C)2022-12-28   (M)2023-07-04



A deny-all and allow-by-exception firewall policy _MUST_ be employed for managing connections to other systems. Organizations _MUST_ ensure the built-in packet filter firewall is configured correctly to employ the default deny rule. Failure to restrict network connectivity to authorized systems permits inbound connections from malicious systems. It also permits outbound connections that may facilitate the exfiltration of data. If you are using a third-party firewall solution, this setting does not apply. [IMPORTANT] ==== Configuring the built-in packet filter firewall to employ the default deny rule has the potential to interfere with applications on the system in an unpredictable manner. Information System Security Officers (ISSOs) may make the risk-based decision not to configure the built-in packet filter firewall to employ the default deny rule to avoid losing functionality, but they are advised to first fully weigh the potential risks posed to their organization. ==== Fix: Enable Firewall and Run following command to block all incoming connections. # /usr/bin/defaults write /Library/Preferences/com.apple.alf.plist "globalstate" -int 2 The changes will reflect after reboot. Note: Setting the default value to 2 blocks all incoming connections, if changing it to 2 please ensure you add exceptions for services like SSH.


Parameter:

[yes/no]


Technical Mechanism:

NOTE: See the firewall supplemental which includes a script that has an example policy to implement this rule.

CCSS Severity:CCSS Metrics:
CCSS Score : 8.3Attack Vector: NETWORK
Exploit Score: 2.8Attack Complexity: LOW
Impact Score: 5.5Privileges Required: LOW
Severity: HIGHUser Interaction: NONE
Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:HScope: UNCHANGED
 Confidentiality: HIGH
 Integrity: LOW
 Availability: HIGH
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:80345


OVAL    1
oval:org.secpod.oval:def:80345
XCCDF    1
xccdf_org.secpod_benchmark_general_Mac_OS_11

© SecPod Technologies