STIGQter STIGQter: STIG Summary: VMware vSphere 6.7 ESXi Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 09 Mar 2021:

The ESXi host must not provide root/administrator-level access to CIM-based hardware monitoring tools or other third-party applications.

DISA Rule

SV-239323r674898_rule

Vulnerability Number

V-239323

Group Title

SRG-OS-000480-VMM-002000

Rule Version

ESXI-67-000070

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Create a role for the CIM account:

From the Host Client, go to Manage >> Security & Users.

Select "Roles" and click "Add Role".

Provide a name for the new role and select Host >> Cim >> Ciminteraction and click "Add".

Add a CIM user account:

From the Host Client, go to Manage >> Security & Users.

Select "Users" and click "Add User".

Provide a name, description, and password for the new user and click "Add".

Assign the CIM account permissions to the host with the new role.

From the Host Client, select the ESXi host, right-click, and go to "Permissions".

Click "Add User", select the CIM account from the drop-down list, select the new CIM role from the drop-down list, and click "Add User".

Check Contents

From the Host Client, select the ESXi host, right-click and go to "Permissions".

Verify the CIM account user role is limited to read only and CIM permissions.

If there is no dedicated CIM account and the root is used for CIM monitoring, this is a finding.

If write access is not required and the access level is not "read-only", this is a finding.

Vulnerability Number

V-239323

Documentable

False

Rule Version

ESXI-67-000070

Severity Override Guidance

From the Host Client, select the ESXi host, right-click and go to "Permissions".

Verify the CIM account user role is limited to read only and CIM permissions.

If there is no dedicated CIM account and the root is used for CIM monitoring, this is a finding.

If write access is not required and the access level is not "read-only", this is a finding.

Check Content Reference

M

Target Key

5326

Comments