Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
SRG-NET-000231-NDM-000170 | SRG-NET-000231-NDM-000170 | SRG-NET-000231-NDM-000170_rule | Medium |
Description |
---|
Session IDs are tokens generated by web applications to uniquely identify an application user's session. Applications will make application decisions and execute business logic based on the session ID. When a user logs out, or when any other session termination event occurs, the application must terminate the user session to minimize the potential for an attacker to hijack that particular user session. |
STIG | Date |
---|---|
Network Device Management Security Requirements Guide | 2013-07-30 |
Check Text ( C-SRG-NET-000231-NDM-000170_chk ) |
---|
Verify the network device is configured to invalidate session identifiers upon administrator logout or other session termination. If the network device is not configured to release and invalidate session identifiers upon user logout or session termination, this is a finding. |
Fix Text (F-SRG-NET-000231-NDM-000170_fix) |
---|
Configure the network device to invalidate session identifiers upon user logout or other session termination. |