The Photon operating system must disable the debug-shell service.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-258873
PHTN-40-000210
SV-258873r991589_rule
Medium
Description
The debug-shell service is intended to diagnose systemd related boot issues with various systemctl commands. Once enabled and following a system reboot, the root shell will be available on tty9. This service must remain disabled until and unless otherwise directed by VMware support.