WN12-GE-000027 - File Transfer Protocol (FTP) servers must be configured to prevent access to the system drive.

Information

The FTP service allows remote users to access shared files and directories. Access outside of the specific directories of shared data could provide access to system resources and compromise the system.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the system to only allow FTP access to specific folders containing the data to be available through the service.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_2012_and_2012_R2_MS_V3R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|I, CCI|CCI-000366, Rule-ID|SV-225438r569185_rule, STIG-ID|WN12-GE-000027, STIG-Legacy|SV-52212, STIG-Legacy|V-1121, Vuln-ID|V-225438

Plugin: Windows

Control ID: 86043840c3920c9ad9823f39f8737927a1509ce8ab2241885e319a2950262fce