GEN002280 - Device files and directories must only be writable by users with a system account or as configured by the vendor.

Information

System device files in writable directories could be modified, removed, or used by an unprivileged user to control system hardware.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Remove the world-writable permission from the device file(s).

Procedure:
# chmod o-w <device file>

Document all changes.

See Also

https://iasecontent.disa.mil/stigs/zip/U_AIX_6-1_V1R14_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Group-ID|V-924, Rule-ID|SV-924r3_rule, STIG-ID|GEN002280, Vuln-ID|V-924

Plugin: Unix

Control ID: 9cbfbf28083d9e23a8566d06d8b8312ecd7d9377a3507763a3f3065869628990