VM : limit-console-connections-two

Information

By default, remote console sessions can be connected to by more than one user at a time. When multiple sessions are activated, each terminal window gets a notification about the new session. If an administrator in the VM logs in using a VMware remote console during their session, a nonadministrator in the VM might connect to the console and observe the administrator's actions. Also, this could result in an administrator losing console access to a virtual machine. For example if a jump box is being used for an open console session, and the admin loses connection to that box, then the console session remains open. Allowing two console sessions permits debugging via a shared session. For highest security, only one remote console session at a time should be allowed.

Solution

Set RemoteDisplay.maxConnections to 2 in the virtual machine configuration file.

See Also

https://www.vmware.com/files/xls/hardeningguide-vsphere5-5-ga-released.xlsx

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-10

Plugin: VMware

Control ID: ad07a8962f50019be4f60e32989e1a75fb200fbb71c1196f1a77c4d2b2566e84