The Arista Multilayer Switch must reveal error messages only to authorized individuals (ISSO, ISSM, and SA).
An XCCDF Rule
Description
<VulnDiscussion>Only authorized personnel should be aware of errors and the details of the errors. Error messages are an indicator of an organization's operational state. Additionally, sensitive account information must not be revealed through error messages to unauthorized personnel or their designated representatives.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>
- ID
- SV-75317r1_rule
- Severity
- Medium
- References
- Updated
Remediation - Manual Procedure
Configure the network device or its associated audit server to reveal error messages only to authorized individuals.
SNMP is used to fulfill this function. An example SNMP configuration is provided below. To configure SNMP according to site-specific policies and procedures, refer to the Arista Configuration Guide Chapter 37
snmp-server engineID local
snmp-server view snmpview system included