CCE-95523-7Platform: cpe:/o:amazon:linux:2, cpe:/o:centos:centos:7, cpe:/o:oracle:linux:7, cpe:/o:oracle:linux:8, cpe:/o:redhat:enterprise_linux:7, cpe:/o:redhat:enterprise_linux:8, cpe:/o:redhat:enterprise_linux:9 | Date: (C)2021-09-28 (M)2023-07-04 |
Description:
In ip6tables the default policy is applied only after all
the applicable rules in the table are examined for a match. Setting the
default policy to 'DROP' implements proper design for a firewall, i.e.
any packets which are not explicitly permitted should not be
accepted.
Fix:
To set the default policy to DROP (instead of ACCEPT) using ip6tables for
the built-in OUTPUT chain which processes outgoing packets, check and run the following steps:
#yum remove -y firewalld
#yum install -y iptables iptables-services
#systemctl enable ip6tables
#ip6tables -P OUTPUT DROP
#service ip6tables save
Note:
In the presence of firewalld package, iptables rules cannot be set as permanent. But removing firewalld package will lead to the removal of all rules currently configured in the machine. So patch is not provided for the rule.
Parameter:
[yes/no]
Technical Mechanism:
In 'ip6tables' the default policy is applied only after all
the applicable rules in the table are examined for a match. Setting the
default policy to 'DROP' implements proper design for a firewall, i.e.
any packets which are not explicitly permitted should not be
accepted.
CCSS Severity: | CCSS Metrics: |
CCSS Score : 10.0 | Attack Vector: NETWORK |
Exploit Score: 3.9 | Attack Complexity: LOW |
Impact Score: 6.0 | Privileges Required: NONE |
Severity: CRITICAL | User Interaction: NONE |
Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H | Scope: CHANGED |
| Confidentiality: HIGH |
| Integrity: HIGH |
| Availability: HIGH |
| |
References: Resource Id | Reference |
---|
SCAP Repo OVAL Definition | oval:org.secpod.oval:def:74479 |
SCAP Repo OVAL Definition | oval:org.secpod.oval:def:84300 |
SCAP Repo OVAL Definition | oval:org.secpod.oval:def:74480 |
SCAP Repo OVAL Definition | oval:org.secpod.oval:def:74481 |
SCAP Repo OVAL Definition | oval:org.secpod.oval:def:74482 |
SCAP Repo OVAL Definition | oval:org.secpod.oval:def:74483 |
SCAP Repo OVAL Definition | oval:org.secpod.oval:def:74484 |
SCAP Repo OVAL Definition | oval:org.secpod.oval:def:74485 |