UCF STIG Viewer Logo

The firewall implementation must prevent unauthorized and unintended information transfer via shared system resources.


Overview

Finding ID Version Rule ID IA Controls Severity
V-37220 SRG-NET-000190-FW-000109 SV-48981r1_rule Medium
Description
The purpose of this control is to prevent information produced by the actions of a prior user, role, or the actions of a process acting on behalf of a prior user or role from being available to any current user, role, or process for obtaining access to a shared system resource (e.g., registers, main memory, or secondary storage) after the resource has been released back to the firewall. Control of information in shared resources is also referred to as object reuse. Verification of this function requires access to the internal programmer's documentation of the firewall manufacturer.
STIG Date
Firewall Security Requirements Guide 2013-04-24

Details

Check Text ( C-45528r2_chk )
Verify the application is designed to prevent unauthorized and unintended information transfer between user sessions.
Verify settings needed to enable or optimize this security feature are enabled and configured.

If the system is not configured to prevent unauthorized and unintended information transfer via shared system resources, this is a finding.
Fix Text (F-42158r2_fix)
Enable settings that prevent unauthorized and unintended information transfer via shared system resources.