Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-24386 | GEN003850 | SV-39864r1_rule | DCPP-1 | High |
Description |
---|
The telnet daemon provides a typically unencrypted remote access service which does not provide for the confidentiality and integrity of user passwords or the remote session. If a privileged user were to log on using this service, the privileged user password could be compromised. |
STIG | Date |
---|---|
SOLARIS 10 SPARC SECURITY TECHNICAL IMPLEMENTATION GUIDE | 2017-01-27 |
Check Text ( None ) |
---|
None |
Fix Text (F-34011r1_fix) |
---|
Disable the telnet daemon. # svcadm disable telnet # svcadm refresh inetd |