The network device must prohibit installation of software without explicit privileged status.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-202105
SRG-APP-000378-NDM-000302
SV-202105r984110_rule
Medium
Description
Allowing anyone to install software, without explicit privileges, creates the risk that untested or potentially malicious software will be installed on the system. This requirement applies to code changes and upgrades for all network devices.
Determine if the network device prohibits installation of software without explicit privileged status. This requirement may be verified by demonstration or configuration review.
If installation of software is not prohibited without explicit privileged status, this is a finding.
Fix Text (F-2232r381945_fix)
Configure the network device to prohibit installation of software without explicit privileged status.