UCF STIG Viewer Logo

The SLES for vRealize must have IEEE 1394 (Firewire) disabled unless needed.


Overview

Finding ID Version Rule ID IA Controls Severity
V-240456 VRAU-SL-000675 SV-240456r671109_rule Medium
Description
Firewire is a common computer peripheral interface. Firewire devices may include storage devices that could be used to install malicious software on a system or exfiltrate data.
STIG Date
VMware vRealize Automation 7.x SLES Security Technical Implementation Guide 2021-06-24

Details

Check Text ( C-43689r671107_chk )
If the SLES for vRealize needs IEEE 1394 (Firewire), this is not applicable.

Check if the firewire module is not disabled:

# grep "install ieee1394 /bin/true" /etc/modprobe.conf /etc/modprobe.conf.local /etc/modprobe.d/*

If no results are returned, this is a finding.
Fix Text (F-43648r671108_fix)
Prevent the SLES for vRealize from loading the firewire module:

# echo "install ieee1394 /bin/true" >> /etc/modprobe.conf.local