2.3.5 Ensure tftp client is not installed

Information

Trivial File Transfer Protocol (TFTP) is a simple protocol for exchanging files between two TCP/IP machines. TFTP servers allow connections from a TFTP Client for sending and receiving files.

TFTP does not have built-in encryption, access control or authentication. This makes it very easy for an attacker to exploit TFTP to gain access to files

Solution

Run the following command to remove tftp :

# yum remove tftp

See Also

https://workbench.cisecurity.org/benchmarks/15963

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Unix

Control ID: 3f04a1e985d9f0b7cc77538d3530fcd59c88211d05c2c5a966a9bc2a6dbd745e