UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

Mozilla FireFox Security Technical Implementation Guide


Overview

Date Finding Count (28)
2020-06-19 CAT I (High): 1 CAT II (Med): 25 CAT III (Low): 2
STIG Description
The Mozilla FireFox Security Technical Implementation Guide (STIG) is published as a tool to improve the security of Department of Defense (DoD) information systems. Comments or proposed revisions to this document should be sent via e-mail to the following address: disa.stig_spt@mail.mil

Available Profiles



Findings (MAC I - Mission Critical Classified)

Finding ID Severity Title
V-17988 High Installed version of Firefox unsupported.
V-15768 Medium FireFox is configured to ask which certificate to present to a web site when a certificate is required.
V-15776 Medium FireFox is configured to use a password store with or without a master password.
V-102879 Medium Fingerprinting protection must be enabled.
V-102877 Medium Telemetry archive must be disabled.
V-102875 Medium Telemetry must be disabled.
V-15986 Medium Firefox is configured to allow JavaScript to disable or replace context menus.
V-19742 Medium Firefox automatically updates installed add-ons and plugins.
V-19744 Medium Firefox automatically checks for updated version of installed Search plugins.
V-102883 Medium Enhanced Tracking Protection must be enabled.
V-102881 Medium Cryptomining protection must be enabled.
V-102885 Medium Extension recommendations must be disabled.
V-79053 Medium Background submission of information to Mozilla must be disabled.
V-102889 Medium Deprecated ciphers must be disabled.
V-6318 Medium The DOD Root Certificate is not installed.
V-15983 Medium Firefox must be configured to allow only TLS.
V-64891 Medium Extensions install must be disabled.
V-15985 Medium Firefox is configured to allow JavaScript to raise or lower windows.
V-15774 Medium Firefox formfill assistance option is disabled.
V-15775 Medium Firefox is configured to autofill passwords.
V-15772 Medium Firefox is not configured to prompt a user before downloading and opening required file types.
V-15773 Medium FireFox plug-in for ActiveX controls is installed.
V-15770 Medium Firefox automatically executes or downloads MIME types which are not authorized for auto-download.
V-15771 Medium Network shell protocol is enabled in FireFox.
V-15778 Medium FireFox is not configured to block pop-up windows.
V-15779 Medium FireFox is configured to allow JavaScript to move or resize windows.
V-97529 Low Firefox Development Tools Must Be Disabled.
V-102887 Low Activity Stream must be disabled.