FireEye - User 'admin' SSH access is disabled

Information

The default username cannot be removed and could be used by an attacker in an attempt to log in. It should be available for local logins in case of emergencies but remote access should be disabled.

Solution

Create another administrative user for remote access and disable such access for the 'admin' account. Edit the configuration and add these lines:\n

username <new_account_name> capability admin\n
no username admin access network enable

Item Details

Audit Name: TNS FireEye

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: FireEye

Control ID: d48a168ce1e6779e302cf6a586d156f4f35920e88bf51d67dfb4c772878b8a0b