8.3.2 Ensure use of the VM console is limited

Information

The VM console enables you to connect to the console of a VM, in effect seeing what a
monitor on a physical server would show. The VM console also provides power
management and removable device connectivity controls. Instead of the VM console, use
native remote management services, such as terminal services and ssh, to interact with
VMs. Grant access to the VM console only when needed, and use custom roles
to provide fine-grained permissions for those people who do need access. By default, the vCenter roles "Virtual
Machine Power User" and "Virtual Machine Administrator" have the "Virtual Machine.Interaction.Console Interaction" privilege.


*Rationale*

The VM console enables you to connect to the console of a virtual machine, in effect seeing
what a monitor on a physical server would show. The VM console also provides power
management and removable device connectivity controls, which might potentially allow a
malicious user to bring down a virtual machine. In addition, it also has a performance
impact on the service console, especially if many VM console sessions are open
simultaneously.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To properly limit use of the VM console, perform the following steps:

1. From the vSphere Client, navigate to Administration\Roles section of vCenter.
2. Create a custom role and choose edit to enable only the minimum needed effective
privileges.
3. Next, select an object in the inventory.
4. Click the Permissions tab to view the user and role pair assignments for that object.
5. Remove any default 'Admin' or 'Power User' roles and assign the new custom role
as needed.

Default Value-The prescribed state is not the default state.

See Also

https://workbench.cisecurity.org/files/2168

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-8, CSCv7|16.1

Plugin: VMware

Control ID: 4d732836de649dace9dc8b218b29ffa7c3e85014cbade7cffe35c4bf253ef55b