STIGQter STIGQter: STIG Summary: Riverbed NetIM OS Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 11 Sep 2025:

Ubuntu OS SSH daemon must prevent remote hosts from connecting to the proxy display.

DISA Rule

SV-275623r1147919_rule

Vulnerability Number

V-275623

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

RIIM-OS-255045

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the SSH server to prevent remote hosts from connecting to the proxy display.

Add or modify the following line in the "/etc/ssh/sshd_config" file:

X11UseLocalhost yes

Restart the SSH daemon for the changes to take effect:

$ sudo systemctl restart sshd.service

Check Contents

Verify the SSH server prevents remote hosts from connecting to the proxy display by using the following command:

$ sudo /usr/sbin/sshd -dd 2>&1 | awk '/filename/ {print $4}' | tr -d '\r' | tr '\n' ' ' | xargs sudo grep -iH 'x11uselocalhost'
/etc/ssh/sshd_config:X11UseLocalhost yes

If "X11UseLocalhost" is set to "no", is commented out, is missing, or conflicting results are returned, this is a finding.

Vulnerability Number

V-275623

Documentable

False

Rule Version

RIIM-OS-255045

Severity Override Guidance

Verify the SSH server prevents remote hosts from connecting to the proxy display by using the following command:

$ sudo /usr/sbin/sshd -dd 2>&1 | awk '/filename/ {print $4}' | tr -d '\r' | tr '\n' ' ' | xargs sudo grep -iH 'x11uselocalhost'
/etc/ssh/sshd_config:X11UseLocalhost yes

If "X11UseLocalhost" is set to "no", is commented out, is missing, or conflicting results are returned, this is a finding.

Check Content Reference

M

Target Key

5706