20.64 Ensure 'TFTP Client' is 'not installed'

Information

This setting provides the transfer of files to and from a remote computer, typically a computer running UNIX, that is running the Trivial File Transfer Protocol (tftp) service or daemon. tftp is typically used by embedded devices or systems that retrieve firmware, configuration information, or a system image during the boot process from a tftp server.

The STIG recommended state for this setting is: Not installed

Unnecessary services increase the attack surface of a system. Some of these services may not support required levels of authentication or encryption or may provide unauthorized access to the system.

Solution

To Uninstall the

TFTP Client

feature:

- Start 'Server Manager'
- Select the server with the role
- Scroll down to 'ROLES AND FEATURES' in the right pane
- Select 'Remove Roles and Features' from the drop-down 'TASKS' list
- Select the appropriate server on the 'Server Selection' page and click 'Next'
- Deselect 'TFTP Client' on the 'Features' page
- Click 'Next' and 'Remove' as prompted (if installed).

Impact:

Trivial File Transfer Protocol (tftp) features, such as the transferring of files, will not be available to users in your organization.

See Also

https://workbench.cisecurity.org/benchmarks/18857

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: 72f6dbe0c74da2c195fa1e779a8bc9f86d5a6f85b1358b376c9220f970664a0d