NET0760 - Configuration auto-loading must be disabled - 'service config'

Information

Devices can find their startup configuration either in their own NVRAM or access it over the network via TFTP or Remote Copy (rcp). Loading the image from the network is taking a security risk since the image could be intercepted by an attacker who could corrupt the image resulting in a denial of service. Configuration auto-loading can be enabled when the device is connected to a non-operational network. Once the device is connected to an operational (i.e. production) network, configuration auto-loading must be disabled.

Solution

Disable the configuration auto-loading feature, when connected to an operational network.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Infrastructure_Router_L3_Switch_V8R29_STIG.zip

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-7(10), CAT|II, Rule-ID|SV-3080r4_rule, STIG-ID|NET0760, Vuln-ID|V-3080

Plugin: Cisco

Control ID: 2325e6f06d1e3821b8e0e52f3a0fb17efe9fc424fb8700e3e9fe5aef603eee19