2.3.4 Ensure telnet client is not installed - rpm

Information

The telnet protocol is insecure and unencrypted. The use of an unencrypted transmission medium could allow an unauthorized user to steal credentials. The ssh package provides an encrypted session and stronger security and is included in most Linux distributions.

Solution

Uninstall telnet using the appropriate package manager or manual installation: # yum remove telnet
# apt-get remove telnet
# zypper remove telnet

See Also

https://workbench.cisecurity.org/files/1856

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv6|3.4

Plugin: Unix

Control ID: 86093f3fb49dae6d5832972967a3b8f43265ad3678e233b9043cd8677d92313c