Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-16083 | SUN0110 | SV-17071r1_rule | ECSC-1 | Medium |
Description |
---|
All Sun Ray firmware is supported by the Sun Ray Desktop Units PROM. Therefore, older versions of the Sun Ray firmware may not be as secure as newer versions. In order to support encryption between the Sun Ray Desktop Unit and the Sun Ray server, the minimum firmware required is version 2.0. All previous Sun Ray Desktop Unit firmware sends traffic in plain text to the server |
STIG | Date |
---|---|
Sun Ray 4 STIG | 2015-04-02 |
Check Text ( C-17126r1_chk ) |
---|
The server may have newer patch version of the firmware installed, but the clients may not have downloaded the new firmware due to policy restrictions. Therefore, it is important to check the firmware on the client, not the server. To check the firmware, go to the Sun Ray Desktop Unit, and perform the following: On the Sun Ray 2fs unit press the (Stop-V) on Sun Keyboard and on the PC keyboards press the (Ctrl-Pause-V). If the version is lower than 2.0, this is a finding. Most likely the version will be 4.0.-127553-02.2008-03.06.15.04 or higher. Note: For other Sun Ray Desktop Units, consult the system administrator or documentation for the key mode combinations. |
Fix Text (F-16189r1_fix) |
---|
Upgrade the firmware to 2.0 or higher, preferably to the most current firmware released from Sun Microsystems. |