3.061 - Unencrypted remote access is permitted to system services.

Information

This is a category 1 finding because when unencrypted access to system services is permitted, an intruder can intercept user identification and passwords that are being transmitted in clear text. This could give an intruder unlimited access to the network.

Solution

Encryption of userid and password information is required.

Encryption of the user data inside the network firewall is also highly recommended.

Encryption of user data coming from or going outside the network firewall is required.

Encryption for administrator data is always required.

Refer to the Enclave Security STIG section on 'FTP and Telnet,' for detailed information on its use.

See Also

http://iasecontent.disa.mil/stigs/zip/Oct2016/U_Windows_Vista_V6R41_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-17(2), CAT|I, CCI|CCI-000068, Rule-ID|SV-29695r1_rule, STIG-ID|3.061, Vuln-ID|V-2908

Plugin: Windows

Control ID: 23e7378e45ac0a932451bab5e55803cdb7788efb9a1490cf4f4bfd729e6d0c40