UCF STIG Viewer Logo

The system must not process ICMP timestamp requests.


Overview

Finding ID Version Rule ID IA Controls Severity
V-22409 GEN003602 SV-38866r1_rule ECSC-1 Low
Description
The processing of Internet Control Message Protocol (ICMP) timestamp requests increases the attack surface of the system.
STIG Date
Draft AIX Security Technical Implementation Guide 2011-08-17

Details

Check Text ( C-37859r1_chk )
Determine if the system is configured to respond to ICMP Timestamp requests.

#lsfit

If there is no rule blocking ICMP packet type of 13 and ICMP packet type of 14, this is a finding.
Fix Text (F-32492r1_fix)
Use SMIT or genfilt commands to configure the system firewall to block ICMP packet types 13, and 14.

#smitty ipsec4

# genfilt