VM : verify-vmsafe-cpumem-enable

Information

The VMsafe CPU/memory API allows a security virtual machine to inspect and modify the contents of the memory and CPU registers on other VMs, for the purpose of detecting and preventing malware attacks. However, an attacker might compromise the VM by making use of this introspection channel; therefore you should monitor for unauthorized usage of this API. A VM must be configured explicitly to accept access by the VMsafe CPU/memory API. This involves three parameters: one to enable the API, one to set the IP address used by the security virtual appliance on the introspection vSwitch, and one to set the port number for that IP address. If the VM is being protected by such a product, then make sure the latter two parameters are set correctly. This should be done only for specific VMs for which you want this protection.

Solution

If the VM is being protected by VMsafe, make sure vmsafe.enable is set to true.

See Also

https://www.vmware.com/files/xls/hardeningguide-vsphere5-5-ga-released.xlsx

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3(10)

Plugin: VMware

Control ID: 4be6a7ad3b6676fd07f304ee22646875e63583073aa000078306242ae823efb7