OL 8 must be configured to disable the ability to use USB mass storage devices.
An XCCDF Rule
Description
<VulnDiscussion>USB mass storage permits easy introduction of unknown devices, thereby facilitating malicious activity.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
- ID
- SV-248837r986386_rule
- Severity
- Medium
- References
- Updated
Remediation - Manual Procedure
Configure OL 8 to disable the ability to use the USB Storage kernel module and to use USB mass storage devices.
$ sudo vi /etc/modprobe.d/blacklist.conf
Add or update the lines: