UCF STIG Viewer Logo

The firewall implementation must only reveal error messages to authorized personnel.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-NET-000313-FW-000173 SRG-NET-000313-FW-000173 SRG-NET-000313-FW-000173_rule Medium
Description
If the application provides too much information in error logs and administrative messages to the screen, this could lead to compromise if the information is available to non authorized personnel. If controls are not in place to protect the error message, an attacker could use the information to his/her advantage and compromise the system based on what is known about the error. The structure and content of error messages need to be carefully considered by the organization and development team. The extent to which the information system is able to identify and handle error conditions is guided by organizational policy and operational requirements.
STIG Date
Firewall Security Requirements Guide 2012-12-10

Details

Check Text ( C-SRG-NET-000313-FW-000173_chk )
Review the firewall configuration to determine if controls are in place to restrict error messages, so only authorized personnel may view them.

If controls are not in place to restrict access to the error messages, this is a finding.
Fix Text (F-SRG-NET-000313-FW-000173_fix)
Configure the firewall implementation to restrict error messages, so only authorized personnel may view them.