Skip to content

AIX must not respond to ICMPv6 echo requests sent to a broadcast address.

An XCCDF Rule

Description

<VulnDiscussion>Responding to broadcast ICMP echo requests facilitates network mapping and provides a vector for amplification attacks.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

ID
SV-215430r991589_rule
Severity
Medium
References
Updated



Remediation - Manual Procedure

Configure the system to not respond to IPv6 multicast ICMP ECHO_REQUESTs by running:
# /usr/sbin/no -p -o bcastping=0