UCF STIG Viewer Logo

The network device must invalidate session identifiers upon user logout or other session termination.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-NET-000231-NDM-000170 SRG-NET-000231-NDM-000170 SRG-NET-000231-NDM-000170_rule Medium
Description
Session IDs are tokens generated by web applications to uniquely identify an application user's session. Applications will make application decisions and execute business logic based on the session ID. When a user logs out, or when any other session termination event occurs, the application must terminate the user session to minimize the potential for an attacker to hijack that particular user session.
STIG Date
Network Device Management Security Requirements Guide 2013-07-30

Details

Check Text ( C-SRG-NET-000231-NDM-000170_chk )
Verify the network device is configured to invalidate session identifiers upon administrator logout or other session termination.

If the network device is not configured to release and invalidate session identifiers upon user logout or session termination, this is a finding.
Fix Text (F-SRG-NET-000231-NDM-000170_fix)
Configure the network device to invalidate session identifiers upon user logout or other session termination.