NET0378 - The firewall must not be listening for telnet service. - 'open ports'

Information

Telnet is an unencrypted service which can be easily exploited, especially when used over a public network such as the internet. With telnet enabled on the firewall, an attacker may be able to send spoofed packets through the firewall and consume the firewall's memory, causing a denial of service on the device. Telnet service is vulnerable to many exploits which can compromise the network device if enabled.

Solution

Disable telnet and verify the firewall is not listening to port 23 or 1467 as shown in the following example:

no telnet 2.0.0.2 255.255.255.255 inside

ciscoasa# show asp table socket

Protocol Socket State Local Address Foreign Address

ciscoasa#

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Firewall_V8R25_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|II, CSCv6|9.1, Rule-ID|SV-87533r1_rule, STIG-ID|NET0378, Vuln-ID|V-72881

Plugin: Cisco

Control ID: 32058b2c26ae1e6e4638101b0f19cced7bcfd82204ec23d4a97babaa84982761