PHTN-67-000065 - The Photon operating system must require users to reauthenticate for privilege escalation.

Information

Without reauthentication, users may access resources or perform tasks for which they do not have authorization.

When operating systems provide the capability to escalate a functional capability, it is critical the user reauthenticate.

Satisfies: SRG-OS-000373-GPOS-00156, SRG-OS-000373-GPOS-00157, SRG-OS-000373-GPOS-00158

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Check the configuration of the '/etc/sudoers' and '/etc/sudoers.d/*' files with the following command:

# visudo
OR
# visudo -f /etc/sudoers.d/<file name>

Remove any occurrences of 'NOPASSWD' tags associated with user accounts with a password hash.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_vSphere_6-7_Y23M07_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-11, CAT|II, CCI|CCI-002038, Rule-ID|SV-239136r856054_rule, STIG-ID|PHTN-67-000065, Vuln-ID|V-239136

Plugin: Unix

Control ID: 316034043886103f1812560bc5ce139dcf3cba23654f47a4c35cd40ec6628e93