Xylok Security Suite must disable nonessential capabilities.
DISA Rule
SV-269579r1053512_rule
Vulnerability Number
V-269579
Group Title
SRG-APP-000141
Rule Version
XYLK-20-000053
Severity
CAT II
CCI(s)
- CCI-000381 - Configure the system to provide only organization-defined mission essential capabilities.
- CCI-001094 - Restrict the ability of individuals to launch organization-defined denial of service attacks against other systems.
- CCI-001095 - Manage capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial of service attacks.
- CCI-001764 - Prevent program execution in accordance with organization-defined policies, rules of behavior, and/or access agreements regarding software program usage and restrictions; rules authorizing the terms and conditions of software program usage.
Weight
10
Fix Recommendation
Revert Xylok to its default configuration, which disables the post-processing test API:
1. As root, open /etc/xylok.conf in a text editor.
2. Delete any ENABLE_PP_TEST_API lines from configuration file.
3. Restart Xylok to apply settings:
# systemctl restart xylok
Check Contents
Verify that Xylok's default ENABLE_PP_TEST_API status is disabled by using the following command:
$ grep ENABLE_PP_TEST_API /etc/xylok.conf
If "ENABLE_PP_TEST_API" exists (case insensitive), this is a finding.
Vulnerability Number
V-269579
Documentable
False
Rule Version
XYLK-20-000053
Severity Override Guidance
Verify that Xylok's default ENABLE_PP_TEST_API status is disabled by using the following command:
$ grep ENABLE_PP_TEST_API /etc/xylok.conf
If "ENABLE_PP_TEST_API" exists (case insensitive), this is a finding.
Check Content Reference
M
Target Key
5665