Free DISA STIG and SRG Library | Vaulted

V-74029

The Cisco IOSISR XE4000 Series router must reveal error messages only to authorized individuals (ISSO, ISSM, and SA).

Finding ID
CISR-ND-000077
Rule ID
SV-88703r2_rule88703r1_rule
Severity
Cat II
CCE
(None)
Group Title
SRG-APP-000267-NDM-000273
CCI
CCI-001314
Target Key
(None)
Documentable
No
Discussion

Only authorized personnel should be aware of errors and the details of the errors. Error messages are an indicator of an organization's operational state. Additionally, sensitive account information must not be revealed through error messages to unauthorized personnel or their designated representatives.

Fix Text

Use CLI views to control who can view error messages. The configuration should look similar to the example below: parser view Senior-Admin secret 5 $1$hW3m$PE.3zCJYeSrvYflFey71R. commands exec include all configure commands exec include all show parser view Auditor secret 5 $1$qb3F$SrdJW2oyyDzq1L94I7eED. commands exec include show logging

Check Content

Verify that the Cisco IOSISR XE4000 Series router is configured to reveal error messages only to authorized individuals. The configuration should look similar to the example below: parser view Senior-Admin secret 5 $1$hW3m$PE.3zCJYeSrvYflFey71R. commands exec include all configure commands exec include all show parser view Auditor secret 5 $1$qb3F$SrdJW2oyyDzq1L94I7eED. commands exec include show logging If it is not configured to reveal error messages only to authorized individuals, this is a finding.