File: rule.yml

package info (click to toggle)
scap-security-guide 0.1.65-1
  • links: PTS, VCS
  • area: main
  • in suites: bookworm
  • size: 71,936 kB
  • sloc: xml: 179,374; sh: 69,771; python: 23,819; makefile: 23
file content (24 lines) | stat: -rw-r--r-- 647 bytes parent folder | download
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
documentation_complete: true

prodtype: rhel7,rhel8

title: 'Remove SSH Server firewalld Firewall exception (Unusual)'

description: |-
    By default, inbound connections to SSH's port are allowed. If
    the SSH server is not being used, this exception should be removed from the
    firewall configuration.
    <br /><br />
    {{{ describe_firewalld_prevent(proto="tcp", service="ssh") }}}

rationale: |-
    If inbound SSH connections are not expected, disallowing access to the SSH port will
    avoid possible exploitation of the port by an attacker.

severity: unknown

identifiers:
    cce@rhel7: CCE-80218-1

references:
    cui: 3.1.12