1.1.4 Ensure 'Password Recovery' is disabled

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Disables the password recovery

Rationale:

Disabling the password recovery is an additional physical control. It will prevent an attacker that will have circumvented all the physical safeguards and being in contact with the security appliance to change the existing login password, enable password and local user password and then hack the system.

Solution

Run the following to disable the password recovery:

HOSTNAME (CONFIG)# NO SERVICE PASSWORD-RECOVERY

See Also

https://benchmarks.cisecurity.org/tools2/cisco/CIS_Cisco_Firewall_Benchmark_v4.0.0.pdf