ESXI-80-000219 The ESXi host must restrict use of the dvFilter network application programming interface (API).

Information

If the organization is not using products that use the dvFilter network API, the host should not be configured to send network information to a virtual machine (VM).

If the API is enabled, an attacker might attempt to connect a virtual machine to it, potentially providing access to the network of other VMs on the host.

If using a product that makes use of this API, verify the host has been configured correctly. If not using such a product, ensure the setting is blank.

Solution

From the vSphere Client, go to Hosts and Clusters.

Select the ESXi Host >> Configure >> System >> Advanced System Settings.

Click "Edit". Select the "Net.DVFilterBindIpAddress" value and remove any incorrect addresses.

or

From a PowerCLI command prompt while connected to the ESXi host, run the following command:

Get-VMHost | Get-AdvancedSetting -Name Net.DVFilterBindIpAddress | Set-AdvancedSetting -Value ""

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_vSphere_8-0_Y24M08_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-258774r959010_rule, STIG-ID|ESXI-80-000219, Vuln-ID|V-258774

Plugin: VMware

Control ID: 735a727222f8372510eacd0fe05b6b1fb612c840f5a0049f1da4a88f53399e13