The network device must be configured to provide a logout mechanism for administrator-initiated communication sessions.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-202085
SRG-APP-000296-NDM-000280
SV-202085r961224_rule
Medium
Description
If an administrator cannot explicitly end a device management session, the session may remain open and be exploited by an attacker; this is referred to as a zombie session.