8.2.8 Ensure PCI and PCIe device passthrough is disabled

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Using the VMware DirectPath I/O feature to pass through a PCI or PCIe device to a virtual machine can result in a potential security vulnerability.

Rationale:

The vulnerability can be triggered by buggy or malicious code running in privileged mode in the guest OS, such as a device driver.

Solution

Using the vSphere Web Client:

Select each VM

Click 'Configure' -> 'Settings' -> 'Virtual Hardware' ->

Remove the PCI/PCIe passthrough device.

Additionally, the following PowerCLI command can be used:

# Add the setting to all VMs
Get-VM | New-AdvancedSetting -Name 'pciPassthru*.present' -value ''

References:

https://docs.vmware.com/en/VMware-vSphere/6.7/com.vmware.vsphere.security.doc/GUID-E5CFB1FB-9216-4C1D-B49A-81AAAC414025.html

See Also

https://workbench.cisecurity.org/files/2816

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: VMware

Control ID: 820509bd4716070674a97424abd64a979e4d1e28be0b25b81a6797ddb6677697