GEN005880 - The NFS server must not allow remote root access.

Information

If the NFS server allows root access to local file systems from remote hosts, this access could be used to compromise the system.

Solution

Edit /etc/exports and remove the root= option for all exports. Re-export the file systems.

See Also

http://iasecontent.disa.mil/stigs/zip/U_STIG_Library_2015_07.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Rule-ID|SV-935r2_rule, STIG-ID|GEN005880, Vuln-ID|V-935

Plugin: Unix

Control ID: d6ba91c0376954745f3cf9230bbd2181d57a26c3a9db21ff3b9674069157d70f