Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-55239 | SRG-APP-000378-NDM-000302 | SV-69485r1_rule | Medium |
Description |
---|
Allowing anyone to install software, without explicit privileges, creates the risk that untested or potentially malicious software will be installed on the system. This requirement applies to code changes and upgrades for all network devices. |
STIG | Date |
---|---|
Network Device Management Security Requirements Guide | 2018-07-02 |
Check Text ( C-55859r1_chk ) |
---|
Determine if the network device prohibits installation of software without explicit privileged status. This requirement may be verified by demonstration or configuration review. If installation of software is not prohibited without explicit privileged status, this is a finding. |
Fix Text (F-60103r1_fix) |
---|
Configure the network device to prohibit installation of software without explicit privileged status. |