GEN002420-ESXI5-00878 - Removable media, remote file systems and file systems that do not contain setuid files must be mounted nosuid

Information

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

As root, log in to the host. Edit /etc/fstab and add the nosuid mount option to all file systems mounted from removable media or network shares, and any file system not containing approved setuid or setgid files.

See Also

http://iasecontent.disa.mil/stigs/zip/U_ESXi5_Server_V1R10_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000366, Group-ID|V-39422, Rule-ID|SV-51280r1_rule, STIG-ID|GEN002420-ESXI5-00878, Vuln-ID|V-39422

Plugin: VMware

Control ID: fb043fe524a7c1f3b22445bf62395e923ca553a990886d2bf08e4dba2101151a