AlmaLinux OS 9 must not have any telnet packages installed.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-269404
ALMA-09-037860
SV-269404r1050287_rule
High
Description
Passwords must be protected at all times, and encryption is the standard method for protecting passwords. If passwords are not encrypted, they can be plainly read (i.e., clear text) and easily compromised.
A telnet server provides an unencrypted remote access mechanism that does not protect the confidentiality of user credentials or the remote session.
If a privileged user were to log on using this service, the privileged user password could be compromised. SSH or other encrypted session methods must be used instead.
Removing the server and client packages prevents inbound and outbound communications from being compromised.