Information
HTTP and Telnet options should not be enabled for device management.
Rationale:
Management access over cleartext services such as HTTP or Telnet could result in a compromise of administrator credentials and other sensitive information related to device management. Theft of either administrative credentials or session data is easily accomplished with a 'Man in the Middle' attack.
Solution
Navigate to Device > Setup > Interfaces > Management.
Set the HTTP and Telnet boxes to unchecked.
Default Value:
Not set. (HTTP and Telnet are disabled by default)
Item Details
Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT
References: 800-53|AC-18, 800-53|AC-18(1), 800-53|AC-18(3), 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, CSCv7|9.2, CSCv7|14.4, CSCv7|16.5
Control ID: 7bc97289789e18ff6d84e670ec2ffffb821c93d0cc4b772c0e01ef9e8d6bc786