GEN002280 - Device files and directories must only be writable by users with a system account or as configured by the vendor.

Information

System device files in writable directories could be modified, removed, or used by an unprivileged user to control system hardware.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Remove the world-writable permission from the device file(s).
Procedure:
# chmod o-w <device file>
Document all changes.

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Rule-ID|SV-924r2_rule, STIG-ID|GEN002280, Vuln-ID|V-924

Plugin: Unix

Control ID: 2e3ba4908c1a2bacd7c58ac2c6af39a3fd1b1bf2d3ccedca7ec5079bf4292877