Ax-OS must limit the number of concurrent sessions to 10 for all accounts and/or account types.
DISA Rule
SV-276001r1122653_rule
Vulnerability Number
V-276001
Group Title
SRG-APP-000001
Rule Version
AXOS-00-000005
Severity
CAT II
CCI(s)
- CCI-000054 - Limit the number of concurrent sessions for each organization-defined account and/or account type to an organization-defined number.
- CCI-001094 - Restrict the ability of individuals to launch organization-defined denial of service attacks against other systems.
- CCI-001095 - Manage capacity, bandwidth, or other redundancy to limit the effects of information flooding types of denial of service attacks.
- CCI-002385 - Protect against or limit the effects of organization-defined types of denial of service events.
Weight
10
Fix Recommendation
From the Axonius Toolbox (accessed via SSH) Main Actions Menu, select the following options:
Compliance Actions >> Advanced Compliance Actions >> Maximum Concurrent Logins >> Enable
Check Contents
From the Axonius Toolbox (accessed via Secure Shell [SSH]) Main Actions Menu, select the following options:
Compliance Actions >> Advanced Compliance Actions >> Maximum Concurrent Logins
If "Current Status: Disable" is shown, this is a finding.
Vulnerability Number
V-276001
Documentable
False
Rule Version
AXOS-00-000005
Severity Override Guidance
From the Axonius Toolbox (accessed via Secure Shell [SSH]) Main Actions Menu, select the following options:
Compliance Actions >> Advanced Compliance Actions >> Maximum Concurrent Logins
If "Current Status: Disable" is shown, this is a finding.
Check Content Reference
M
Target Key
5710