Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-36354 | SRG-APP-191-MDM-289-SRV | SV-47758r1_rule | Medium |
Description |
---|
Without a trusted communication path, the MDM server is vulnerable to a man in the middle attack. |
STIG | Date |
---|---|
Mobile Device Manager Security Requirements Guide | 2013-01-24 |
Check Text ( C-44596r1_chk ) |
---|
Review the MDM server configuration to determine whether the MDM server establishes a trusted path for an administrator to enter authentication credentials (password or CAC PIN). If the MDM server does not provide a trusted path, this is a finding. |
Fix Text (F-40886r1_fix) |
---|
Configure the MDM server to establish a trusted communications path between the Administrator and the systems authentication mechanism. |