UCF STIG Viewer Logo

The portmap or rpcbind service must not be installed unless needed.


Overview

Finding ID Version Rule ID IA Controls Severity
V-22430 GEN003815 SV-35088r1_rule ECSC-1 Medium
Description
The portmap and rpcbind services increase the attack surface of the system and should only be used when needed. The portmap or rpcbind services are used by a variety of services using Remote Procedure Calls (RPCs).
STIG Date
HP-UX 11.31 Security Technical Implementation Guide 2018-09-14

Details

Check Text ( C-36535r1_chk )
If the system needs the portmap service to operate, this is not applicable. In
order to inspect the HP-UX portmapper protocol:
# rpcinfo -p

If the service is running while supporting a required service, i.e., mountd/nfs(d),
this is not a finding.

If the portmap service is installed/running and not required to support any service(s),
this is a finding.
Fix Text (F-31899r1_fix)
If the portmap or rpcbind service is part of a removable package,
consult vendor documentation for the procedure to remove the package. If the
service cannot be removed, prevent service activation by removing all permissions
from the executable.

Procedure:
# whereis rpcinfo
# chmod 0000