ESXI-65-000041 - The ESXi host must set a timeout to automatically disable idle sessions after 10 minutes.

Information

If a user forgets to log out of their SSH session, the idle connection will remains open indefinitely, increasing the potential for someone to gain privileged access to the host. The ESXiShellInteractiveTimeOut allows you to automatically terminate idle shell sessions.

Solution

From the vSphere Web Client select the ESXi Host and go to Configure >> System >> Advanced System Settings. Click Edit and select the UserVars.ESXiShellInteractiveTimeOut value and configure it to 600.

or

From a PowerCLI command prompt while connected to the ESXi host run the following commands:

Get-VMHost | Get-AdvancedSetting -Name UserVars.ESXiShellInteractiveTimeOut | Set-AdvancedSetting -Value 600

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_vSphere_6-5_Y23M07_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-10, CAT|II, CCI|CCI-001133, Rule-ID|SV-207642r878140_rule, STIG-ID|ESXI-65-000041, STIG-Legacy|SV-104115, STIG-Legacy|V-94029, Vuln-ID|V-207642

Plugin: VMware

Control ID: 21693d8be9ce2c0c8683e98810074ce732b1fa7f21a70dd211dd7c0b398d7574