[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256288

 
 

909

 
 

199146

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-94533-7

Platform: cpe:/a:mozilla:firefox_rpmDate: (C)2021-06-15   (M)2023-07-04



Although current versions of Firefox have this set to disabled by default, use of this option can be harmful. This would allow the browser to access the Windows shell. This could allow access to the underlying system. This check verifies that the default setting has not been changed.


Parameter:

[no/yes]


Technical Mechanism:

Procedure: Set the value of "network.protocol-handler.external.shell" to "false" and lock using the Mozilla.cfg file.

CCSS Severity:CCSS Metrics:
CCSS Score : 8.6Attack Vector: NETWORK
Exploit Score: 3.9Attack Complexity: LOW
Impact Score: 4.7Privileges Required: NONE
Severity: HIGHUser Interaction: NONE
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:HScope: UNCHANGED
 Confidentiality: LOW
 Integrity: LOW
 Availability: HIGH
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:60304


OVAL    1
oval:org.secpod.oval:def:60304
XCCDF    1
xccdf_org.secpod_benchmark_stig_FIREFOX

© SecPod Technologies