[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256288

 
 

909

 
 

199146

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-99423-3

Platform: cpe:/o:redhat:enterprise_linux:9Date: (C)2023-07-04   (M)2023-07-14



If there is no need to mount directories and file systems to Windows systems, then smb service can be disabled to reduce the potential attack surface.Audit:Run the following command to verify `smb` is not enabled: # systemctl is-enabled smbVerify result is not `enabled`.Fix:Run the following command to disable `smb`:# systemctl --now disable smb


Parameter:

[yes/no]


Technical Mechanism:

If there is no need to mount directories and file systems to Windows systems, then smb service can be disabled to reduce the potential attack surface. Run the following command to disable `smb`: # systemctl --now disable smb

CCSS Severity:CCSS Metrics:
CCSS Score : 6.6Attack Vector: NETWORK
Exploit Score: 0.7Attack Complexity: HIGH
Impact Score: 5.9Privileges Required: HIGH
Severity: MEDIUMUser Interaction: NONE
Vector: AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:HScope: UNCHANGED
 Confidentiality: HIGH
 Integrity: HIGH
 Availability: HIGH
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:86916


OVAL    1
oval:org.secpod.oval:def:86916
XCCDF    1
xccdf_org.secpod_benchmark_general_RHEL_9

© SecPod Technologies