Information
The HostbasedAuthentication parameter specifies if authentication is allowed through trusted hosts via the use ofrhosts or /etc/hosts.equiv along with successful public key client host authentication.
Even though therhosts files are ineffective if support is disabled in /etc/pam.conf disabling the ability to userhosts files in SSH provides an additional layer of protection.
Solution
Edit the /etc/ssh/sshd_config file to set the HostbasedAuthentication parameter to no above any Include and Match entries as follows:
HostbasedAuthentication no
Note: First occurrence of an option takes precedence, Match set statements withstanding. If Include locations are enabled, used, and order of precedence is understood in your environment, the entry may be created in a file in Include location.