VCWN-06-000025 - The system must disable the managed object browser at all times, when not required for troubleshooting or maintenance.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The managed object browser provides a way to explore the object model used by the vCenter to manage the vSphere environment; it enables configurations to be changed as well. This interface is used primarily for debugging, and might potentially be used to perform malicious configuration changes or actions.

NOTE: Nessus has not evaluted this check. It is included for informational purposes.

Solution

If the datastore browser is enabled and required for object maintenance, no fix is immediately required.

Disable the managed object browser:
Determine the location of the vpxd.cfg file on the Windows host.
Edit the file and locate the <vpxd> ... </vpxd> element.
Ensure the following element is set. <enableDebugBrowse>false</enableDebugBrowse>

Restart the vCenter Service to ensure the configuration file change(s) are in effect.

See Also

http://iasecontent.disa.mil/stigs/zip/U_VMware_vSphere_6-0_vCenter_Server_for_Windows_V1R3_STIG.zip

Item Details

References: CAT|III, CCI|CCI-000366, Group-ID|V-63987, Rule-ID|SV-78477r1_rule, STIG-ID|VCWN-06-000025

Plugin: VMware

Control ID: 8ade49b6f2d13a26496666dab7bc8138e164ea6dd1926add93dbe146adac1867