Finding ID |
Severity |
Title |
Description |
V-259165
|
Medium |
The vCenter Envoy service must set a limit on remote connections. |
Envoy client connections must be limited to preserve system resources and continue servicing connections without interruption. Without a limit set, the system would be vulnerable to a trivial denial-of-service attack where connections are created en masse and vCenter resources are entirely consumed.
Envoy comes hard coded with a tested and... |
V-259164
|
Medium |
The vCenter Envoy service log files must be sent to a central log server. |
Writing events to a centralized management audit system offers many benefits to the enterprise over having dispersed logs. Centralized management of audit records and logs provides for efficiency in maintenance and management of records, enterprise analysis of events, and backup and archiving of event records enterprise-wide. The web server and... |
V-259163
|
Medium |
The vCenter Rhttpproxy service log files must be sent to a central log server. |
Writing events to a centralized management audit system offers many benefits to the enterprise over having dispersed logs. Centralized management of audit records and logs provides for efficiency in maintenance and management of records, enterprise analysis of events, and backup and archiving of event records enterprise-wide. The web server and... |
V-259162
|
Medium |
The vCenter Envoy service private key file must be protected from unauthorized access. |
Envoy's private key is used to prove the identity of the server to clients and securely exchange the shared secret key used to encrypt communications between the web server and clients.
By gaining access to the private key, an attacker can pretend to be an authorized server and decrypt the... |
V-259161
|
Medium |
The vCenter Envoy and Rhttpproxy service log files permissions must be set correctly. |
Log data is essential in the investigation of events. If log data were to become compromised, then competent forensic analysis and discovery of the true source of potentially malicious system activity would be difficult, if not impossible, to achieve. In addition, access to log records provides information an attacker could... |