UCF STIG Viewer Logo

The system must not respond to ICMP timestamp requests sent to a broadcast address.


Overview

Finding ID Version Rule ID IA Controls Severity
GEN003604-ESXI5-PF GEN003604-ESXI5-PF GEN003604-ESXI5-PF_rule Medium
Description
The processing of Internet Control Message Protocol (ICMP) timestamp requests increases the attack surface of the system. Responding to broadcast ICMP timestamp requests facilitates network mapping and provides a vector for amplification attacks. Applicable, but permanent finding - The hypervisor does not support this functionality (No ndd network tuning facility).
STIG Date
VMware ESXi v5 Security Technical Implementation Guide 2013-01-15

Details

Check Text ( C-GEN003604-ESXI5-PF_chk )
ESXi does not support this requirement. This is a permanent finding.
Fix Text (F-GEN003604-ESXI5-PF_fix)
This requirement is a permanent finding and cannot be fixed. An appropriate mitigation for the system must be implemented but this finding cannot be considered fixed.