STIGQter STIGQter: STIG Summary: MS Exchange 2010 Edge Transport Server STIG Version: 1 Release: 15 Benchmark Date: 26 Apr 2019:

Receive Connectors must control the number of recipients per message.

DISA Rule

SV-43992r2_rule

Vulnerability Number

V-33572

Group Title

Exch-2-727

Rule Version

Exch-2-727

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Open the Exchange Management Shell and enter the following command:

Set-ReceiveConnector -Identity <'ReceiveConnector'> -MaxRecipientsPerMessage 5000 or other value as identified by the EDSP.

Check Contents

Obtain the Email Domain Security Plan (EDSP) and locate the 'Maximum Recipients per Message' value:

Open the Exchange Management Shell and enter the following command:

Get-ReceiveConnector | Select Name, Identity, MaxRecipientsPerMessage

For each receive connector, evaluate the 'MaxRecipientsPerMessage' value.

If the value of 'Maximum Recipients per Message' is set to a value other than 5000, and has signoff and risk acceptance in the EDSP, this is not a finding.

If the value of 'MaxRecipientsPerMessage' is not set to 5000, this is a finding.

Vulnerability Number

V-33572

Documentable

False

Rule Version

Exch-2-727

Severity Override Guidance

Obtain the Email Domain Security Plan (EDSP) and locate the 'Maximum Recipients per Message' value:

Open the Exchange Management Shell and enter the following command:

Get-ReceiveConnector | Select Name, Identity, MaxRecipientsPerMessage

For each receive connector, evaluate the 'MaxRecipientsPerMessage' value.

If the value of 'Maximum Recipients per Message' is set to a value other than 5000, and has signoff and risk acceptance in the EDSP, this is not a finding.

If the value of 'MaxRecipientsPerMessage' is not set to 5000, this is a finding.

Check Content Reference

M

Target Key

1995

Comments