RHEL-08-040070 - The RHEL 8 file system automounter must be disabled unless required.

Information

Automatically mounting file systems permits easy introduction of unknown devices, thereby facilitating malicious activity.

Solution

Configure the operating system to disable the ability to automount devices.

Turn off the automount service with the following commands:

$ sudo systemctl stop autofs
$ sudo systemctl disable autofs

If 'autofs' is required for Network File System (NFS), it must be documented with the ISSO.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_8_V2R1_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-3, CAT|II, CCI|CCI-000778, Rule-ID|SV-230502r1017284_rule, STIG-ID|RHEL-08-040070, Vuln-ID|V-230502

Plugin: Unix

Control ID: 6a5b330fb6e54ab9631e640c0c97d3823febe1fbfed9359ed4256f671915fdd8