The UEM server must verify remote disconnection when non-local maintenance and diagnostic sessions are terminated.
An XCCDF Rule
Description
If the remote connection is not closed and verified as closed, the session may remain open and be exploited by an attacker; this is referred to as a zombie session. Remote connections must be disconnected and verified as disconnected when non-local maintenance sessions have been terminated and are no longer available for use.
- ID
- SV-234556r961560_rule
- Version
- SRG-APP-000413-UEM-000284
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Configure the UEM server to verify remote disconnection when non-local maintenance and diagnostic sessions are terminated.