Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-22429 | GEN003810 | SV-45785r1_rule | Medium |
Description |
---|
The portmap and rpcbind services increase the attack surface of the system and should only be used when needed. The portmap or rpcbind services are used by a variety of services using Remote Procedure Calls (RPCs). |
STIG | Date |
---|---|
SUSE Linux Enterprise Server v11 for System z Security Technical Implementation Guide | 2018-09-19 |
Check Text ( C-43122r1_chk ) |
---|
Check the status of the portmap and/or rpcbind service. # rcportmap status # rcrpcbind status If the service is running, this is a finding. |
Fix Text (F-39179r1_fix) |
---|
Shutdown and disable the portmap and/or rpcbind service. # rcportmap stop; insserv –r portmap # rcrpcbind stop; insserv –r rpcbind |