Skip to content

Network devices must provide a logoff capability for administrator-initiated communication sessions.

An XCCDF Rule

Description

If an administrator cannot explicitly end a device management session, the session may remain open and be exploited by an attacker; this is referred to as a zombie session.

ID
SV-80715r1_rule
Version
HFFS-ND-000082
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Configure the HP FlexFabric Switch to provide a logoff capability for administrator-initiated communication sessions.

[HP] Ctrl + z
<HP> quit