Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-37322 | SRG-NET-000273-FW-000152 | SV-49083r1_rule | Medium |
Description |
---|
The extent to which the firewall is able to identify and handle error conditions is guided by organizational policy and operational requirements. However, these error messages must not reveal information captured in the log data that could compromise either the device or the network. Hence, the content of error messages (within the audit logs) and alerts sent to the system administrators must be carefully considered. This requirement includes device or firewall application error conditions, as well as log alerts. Firewall error messages can potentially provide a wealth of information to an attacker, such as providing a security flaw within the firewall implementation itself, allowing inadvertent access or exploitation of the resource records. |
STIG | Date |
---|---|
Firewall Security Requirements Guide | 2013-04-24 |
Check Text ( C-45570r1_chk ) |
---|
Review the error message sent by the system. (These messages may be part of the ACLs or policy filters or may be in a message repository, depending on the product used.) Verify the system notifications for error messages or alerts do not contain sensitive or potentially harmful information, as defined by the organization. If sensitive or potentially harmful information, as defined by the organization, is included as part of the audit event entries or the alert messages, this is a finding. |
Fix Text (F-42247r1_fix) |
---|
Remove sensitive or potentially harmful information, as defined by the organization, from the logged notification messages for error conditions or alerts. |