V-237095 | Medium | Unauthorized removal, connection and modification of devices must be prevented on the virtual machine. | In a virtual machine, users and processes without root or administrator privileges can connect or disconnect devices, such as network adaptors and CD-ROM drives, and can modify device settings.... |
V-237096 | Medium | The virtual machine must not be able to obtain host information from the hypervisor. | If enabled, a VM can obtain detailed information about the physical host. The default value for the parameter is FALSE. This setting should not be TRUE unless a particular VM requires this... |
V-237090 | Medium | Unauthorized serial devices must be disconnected on the virtual machine. | Ensure that no device is connected to a virtual machine if it is not required. For example, floppy, serial and parallel ports are rarely used for virtual machines in a datacenter environment, and... |
V-237091 | Medium | Unauthorized USB devices must be disconnected on the virtual machine. | Ensure that no device is connected to a virtual machine if it is not required. For example, floppy, serial and parallel ports are rarely used for virtual machines in a datacenter environment, and... |
V-237092 | Medium | Console connection sharing must be limited on the virtual machine. | By default, remote console sessions can be connected to by more than one user at a time. When multiple sessions are activated, each terminal window gets a notification about the new session. If... |
V-237093 | Medium | Console access through the VNC protocol must be disabled on the virtual machine. | The VM console enables you to connect to the console of a virtual machine, in effect seeing what a monitor on a physical server would show. This console is also available via the VNC protocol and... |
V-237072 | Medium | HGFS file transfers must be disabled on the virtual machine. | Setting isolation.tools.hgfsServerSet.disable to true disables registration of the guest's HGFS server with the host. APIs that use HGFS to transfer files to and from the guest operating system,... |
V-237070 | Medium | Virtual disk erasure must be disabled on the virtual machine. | Shrinking and wiping (erasing) a virtual disk reclaims unused space in it. If there is empty space in the disk, this process reduces the amount of space the virtual disk occupies on the host... |
V-237071 | Medium | Independent, non-persistent disks must be not be used on the virtual machine. | The security issue with nonpersistent disk mode is that successful attackers, with a simple shutdown or reboot, might undo or remove any traces that they were ever on the machine. To safeguard... |
V-237089 | Medium | Unauthorized parallel devices must be disconnected on the virtual machine. | Ensure that no device is connected to a virtual machine if it is not required. For example, floppy, serial and parallel ports are rarely used for virtual machines in a datacenter environment, and... |
V-237087 | Medium | Unauthorized floppy devices must be disconnected on the virtual machine. | Ensure that no device is connected to a virtual machine if it is not required. For example, floppy, serial and parallel ports are rarely used for virtual machines in a datacenter environment, and... |
V-237069 | Medium | Virtual disk shrinking must be disabled on the virtual machine. | Shrinking a virtual disk reclaims unused space in it. If there is empty space in the disk, this process reduces the amount of space the virtual disk occupies on the host drive. Normal users and... |
V-237103 | Medium | Encryption must be enabled for vMotion on the virtual machine. | vMotion migrations in vSphere 6.0 and earlier transferred working memory and CPU state information in clear text over the vMotion network. As of vSphere 6.5 this transfer can be transparently... |
V-237100 | Medium | Use of the virtual machine console must be minimized. | The VM console enables a connection to the console of a virtual machine, in effect seeing what a monitor on a physical server would show. The VM console also provides power management and... |
V-237101 | Medium | The virtual machine guest operating system must be locked when the last console connection is closed. | When accessing the VM console the guest OS must be locked when the last console user disconnects, limiting the possibility of session hijacking. This setting only applies to Windows-based VMs with... |
V-237098 | Low | Access to virtual machines through the dvfilter network APIs must be controlled. | An attacker might compromise a VM by making use the dvFilter API. Configure only those VMs to use the API that need this access. |
V-237099 | Low | System administrators must use templates to deploy virtual machines whenever possible. | By capturing a hardened base operating system image (with no applications installed) in a template, ensure all virtual machines are created with a known baseline level of security. Then use this... |
V-237094 | Low | Informational messages from the virtual machine to the VMX file must be limited on the virtual machine. | The configuration file containing these name-value pairs is limited to a size of 1MB. If not limited, VMware tools in the guest OS are capable of sending a large and continuous data stream to the... |
V-237097 | Low | Shared salt values must be disabled on the virtual machine. | When salting is enabled (Mem.ShareForceSalting=1 or 2) in order to share a page between two virtual machines both salt and the content of the page must be same. A salt value is a configurable... |
V-237078 | Low | The unexposed feature keyword isolation.tools.ghi.trayicon.disable must be set on the virtual machine. | Some virtual machine advanced settings parameters do not apply on vSphere because VMware virtual machines work on both vSphere and hosted virtualization platforms such as Workstation and Fusion.... |
V-237079 | Low | The unexposed feature keyword isolation.tools.unity.disable must be set on the virtual machine. | Some virtual machine advanced settings parameters do not apply on vSphere because VMware virtual machines work on both vSphere and hosted virtualization platforms such as Workstation and Fusion.... |
V-237076 | Low | The unexposed feature keyword isolation.tools.ghi.protocolhandler.info.disable must be set on the virtual machine. | Some virtual machine advanced settings parameters do not apply on vSphere because VMware virtual machines work on both vSphere and hosted virtualization platforms such as Workstation and Fusion.... |
V-237077 | Low | The unexposed feature keyword isolation.ghi.host.shellAction.disable must be set on the virtual machine. | Some virtual machine advanced settings parameters do not apply on vSphere because VMware virtual machines work on both vSphere and hosted virtualization platforms such as Workstation and Fusion.... |
V-237074 | Low | The unexposed feature keyword isolation.tools.ghi.launchmenu.change must be set on the virtual machine. | Some virtual machine advanced settings parameters do not apply on vSphere because VMware virtual machines work on both vSphere and hosted virtualization platforms such as Workstation and Fusion.... |
V-237075 | Low | The unexposed feature keyword isolation.tools.memSchedFakeSampleStats.disable must be set on the virtual machine. | Some virtual machine advanced settings parameters do not apply on vSphere because VMware virtual machines work on both vSphere and hosted virtualization platforms such as Workstation and Fusion.... |
V-237073 | Low | The unexposed feature keyword isolation.tools.ghi.autologon.disable must be set on the virtual machine. | Some virtual machine advanced settings parameters do not apply on vSphere because VMware virtual machines work on both vSphere and hosted virtualization platforms such as Workstation and Fusion.... |
V-237088 | Low | Unauthorized CD/DVD devices must be disconnected on the virtual machine. | Ensure that no device is connected to a virtual machine if it is not required. For example, floppy, serial and parallel ports are rarely used for virtual machines in a datacenter environment, and... |
V-237086 | Low | The unexposed feature keyword isolation.tools.guestDnDVersionSet.disable must be set on the virtual machine. | Some virtual machine advanced settings parameters do not apply on vSphere because VMware virtual machines work on both vSphere and hosted virtualization platforms such as Workstation and Fusion.... |
V-237085 | Low | The unexposed feature keyword isolation.tools.vmxDnDVersionGet.disable must be set on the virtual machine. | Some virtual machine advanced settings parameters do not apply on vSphere because VMware virtual machines work on both vSphere and hosted virtualization platforms such as Workstation and Fusion.... |
V-237084 | Low | The unexposed feature keyword isolation.tools.unity.windowContents.disable must be set on the virtual machine. | Some virtual machine advanced settings parameters do not apply on vSphere because VMware virtual machines work on both vSphere and hosted virtualization platforms such as Workstation and Fusion.... |
V-237083 | Low | The unexposed feature keyword isolation.tools.unityActive.disable must be set on the virtual machine. | Some virtual machine advanced settings parameters do not apply on vSphere because VMware virtual machines work on both vSphere and hosted virtualization platforms such as Workstation and Fusion.... |
V-237082 | Low | The unexposed feature keyword isolation.tools.unity.taskbar.disable must be set on the virtual machine. | Some virtual machine advanced settings parameters do not apply on vSphere because VMware virtual machines work on both vSphere and hosted virtualization platforms such as Workstation and Fusion.... |
V-237081 | Low | The unexposed feature keyword isolation.tools.unity.push.update.disable must be set on the virtual machine. | Some virtual machine advanced settings parameters do not apply on vSphere because VMware virtual machines work on both vSphere and hosted virtualization platforms such as Workstation and Fusion.... |
V-237080 | Low | The unexposed feature keyword isolation.tools.unityInterlockOperation.disable must be set on the virtual machine. | Some virtual machine advanced settings parameters do not apply on vSphere because VMware virtual machines work on both vSphere and hosted virtualization platforms such as Workstation and Fusion.... |
V-237065 | Low | Copy operations must be disabled on the virtual machine. | Copy and paste operations are disabled by default; however, by explicitly disabling this feature it will enable audit controls to check that this setting is correct. Copy, paste, drag and drop, or... |
V-237067 | Low | GUI functionality for copy/paste operations must be disabled on the virtual machine. | Copy and paste operations are disabled by default; however, by explicitly disabling this feature it will enable audit controls to check that this setting is correct. Copy, paste, drag and drop, or... |
V-237066 | Low | Drag and drop operations must be disabled on the virtual machine. | Copy and paste operations are disabled by default; however, by explicitly disabling this feature it will enable audit controls to check that this setting is correct. Copy, paste, drag and drop, or... |
V-237068 | Low | Paste operations must be disabled on the virtual machine. | Copy and paste operations are disabled by default; however, by explicitly disabling this feature it will enable audit controls to check that this setting is correct. Copy, paste, drag and drop, or... |
V-237102 | Low | 3D features on the virtual machine must be disabled when not required. | It is recommended that 3D acceleration be disabled on virtual machines that do not require 3D functionality, (e.g. most server workloads or desktops not using 3D applications). |