Skip to content

There is no restriction on where a MFD or a printer can be remotely managed.

An XCCDF Rule

Description

<VulnDiscussion>Since unrestricted access to the MFD or printer for management is not required the restricting the management interface to specific IP addresses decreases the exposure of the system to malicious actions. If the MFD or printer is compromised it could lead to a denial of service or a compromise of sensitive data. The SA will ensure devices can only be remotely managed by SA’s or printer administrators from specific IPs (SA workstations and print spooler).</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility>System Administrator</Responsibility><IAControls>DCBP-1</IAControls>

ID
SV-7009r1_rule
Severity
High
Updated



Remediation - Manual Procedure

Restrict access to the MFD's or printer's management function to a specific set of IP addresses.  If the device lacks this functionality use an ACL in a router, firewall or switch to restrict the access.