Ensure tftp server is not enabled

Information

TFTP does not support authentication nor does it ensure the confidentiality or integrity of data. It is recommended that TFTP be removed, unless there is a specific need for TFTP. In that case, extreme caution must be used when configuring the services.

Solution

Comment out or remove any lines starting with tftp from /etc/inetd.conf and /etc/inetd.d/*.
Set disable = yes on all tftp services in /etc/xinetd.conf and /etc/xinetd.d/*.

See Also

https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623.html