Skip to content

VMware vSphere 7.0 vCenter Appliance Photon OS Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • The Photon operating system must be configured so the "/etc/cron.allow" file is protected from unauthorized modification.

    <VulnDiscussion>If cron files and folders are accessible to unauthorized users, malicious jobs may be created.</VulnDiscussion><Fals...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • The Photon operating system must be configured so that all cron jobs are protected from unauthorized modification.

    &lt;VulnDiscussion&gt;If cron files and folders are accessible to unauthorized users, malicious jobs may be created.&lt;/VulnDiscussion&gt;&lt;Fals...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • The Photon operating system must be configured so that all cron paths are protected from unauthorized modification.

    &lt;VulnDiscussion&gt;If cron files and folders are accessible to unauthorized users, malicious jobs may be created.&lt;/VulnDiscussion&gt;&lt;Fals...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • The Photon operating system must not forward IPv4 or IPv6 source-routed packets.

    &lt;VulnDiscussion&gt;Source routing is an Internet Protocol mechanism that allows an IP packet to carry information, a list of addresses, that tel...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group
  • The Photon operating system must not respond to IPv4 Internet Control Message Protocol (ICMP) echoes sent to a broadcast address.

    &lt;VulnDiscussion&gt;Responding to broadcast (ICMP) echoes facilitates network mapping and provides a vector for amplification attacks.&lt;/VulnDi...
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    <GroupDescription></GroupDescription>
    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules