ESXI5-VM-000047 - The system must not send host information to guests

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

If enabled, a VM can obtain detailed information about the physical host. The default value for the parameter is FALSE. This setting should not be TRUE unless a particular VM requires this information for performance monitoring. An adversary potentially can use this information to inform further attacks on the host.

Solution

As root, log in to the ESXi host and locate the VM's vmx file.
find / | grep vmx

Add the following to the VM's vmx file.
keyword = 'keyval'

Where:
keyword = tools.guestlib.enableHostInfo
keyval = FALSE

See Also

http://iasecontent.disa.mil/stigs/zip/U_ESXi5_Virtual_Machine_V1R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CAT|II, CCI|CCI-000366, Group-ID|V-39501, Rule-ID|SV-51359r1_rule, STIG-ID|ESXI5-VM-000047, Vuln-ID|V-39501

Plugin: VMware

Control ID: 9feb0f00fc2d05bd7aa0d6cda3ee0a53c44ebcdaf2fe46031f38b34d5e65d35e