Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
SRG-NET-000313-FW-000173 | SRG-NET-000313-FW-000173 | SRG-NET-000313-FW-000173_rule | Medium |
Description |
---|
If the application provides too much information in error logs and administrative messages to the screen, this could lead to compromise if the information is available to non authorized personnel. If controls are not in place to protect the error message, an attacker could use the information to his/her advantage and compromise the system based on what is known about the error. The structure and content of error messages need to be carefully considered by the organization and development team. The extent to which the information system is able to identify and handle error conditions is guided by organizational policy and operational requirements. |
STIG | Date |
---|---|
Firewall Security Requirements Guide | 2012-12-10 |
Check Text ( C-SRG-NET-000313-FW-000173_chk ) |
---|
Review the firewall configuration to determine if controls are in place to restrict error messages, so only authorized personnel may view them. If controls are not in place to restrict access to the error messages, this is a finding. |
Fix Text (F-SRG-NET-000313-FW-000173_fix) |
---|
Configure the firewall implementation to restrict error messages, so only authorized personnel may view them. |