8.1.2 Ensure only one remote console connection is permitted to a VM at any time

Information

By default, remote console sessions can be connected to by more than one user at a time.
Permit only one remote console connection to a VM at a time. Other attempts will be
rejected until the first connection disconnects.

*Rationale*

When multiple sessions are activated, each terminal window gets a notification about the
new session. If an administrator in the VM logs in using a VMware remote console during
their session, a non-administrator in the VM can connect to the console and observe the
administrator's actions. Also, this could result in an administrator losing console access to a
VM. For example, if a jump box is being used for an open console session, and the admin
loses a connection to that box, the console session remains open. Allowing two console
sessions permits debugging via a shared session. For highest security, only one remote
console session at a time should be allowed.

Solution

To implement the recommended configuration state, run the following PowerCLI
command-# Add the setting to all VMs
Get-VM | New-AdvancedSetting -Name 'RemoteDisplay.maxConnections' -value 1Impact-Only one remote console connection to the VM will be permitted. Other attempts will be
rejected until the first session disconnects.Default Value-The prescribed state is not the default state.

See Also

https://workbench.cisecurity.org/files/2168

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv7|9.2

Plugin: VMware

Control ID: 28460b87eec2372ac44af5e7bbcf8b1f639076e3ebeb9dfaad9ef3867ab11b6f