[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-95497-4

Platform: cpe:/o:amazon:linux:2, cpe:/o:centos:centos:7, cpe:/o:oracle:linux:7, cpe:/o:oracle:linux:8, cpe:/o:redhat:enterprise_linux:7, cpe:/o:redhat:enterprise_linux:8, cpe:/o:redhat:enterprise_linux:9Date: (C)2021-03-05   (M)2023-07-04



Description: The vFAT filesystem format is primarily used on older windows systems and portable USB drives or flash modules. It comes in three types FAT12 , FAT16 , and FAT32 all of which are supported by the vfat kernel module. Rationale: Removing support for unneeded filesystem types reduces the local attack surface of the system. If this filesystem type is not needed, disable it. Audit: If utilizing UEFI the vFAT filesystem format is required. If this case, ensure that the vFAT filesystem is only used where appropriate Run the following command grep -E -i 'svfats' /etc/fstab And review that any output is appropriate for your environment If not utilizing UEFI Run the following commands and verify the output is as indicated: # modprobe -n -v vfat install /bin/true # lsmod | grep vfat Remediation: Edit or create a file in the /etc/modprobe.d/ directory ending in .conf Example: vim /etc/modprobe.d/vfat.conf install vfat /bin/true Run the following command to unload the vfat module: # rmmod vfat Impact: The FAT filesystem format is used by UEFI systems for the EFI boot partition. Disabling the vfat module can prevent boot on UEFI systems. FAT filesystems are often used on portable USB sticks and other flash media which are commonly used to transfer files between workstations, removing VFAT support may prevent the ability to transfer files in this way.


Parameter:

[yes/no]


Technical Mechanism:

Edit or create a file in the /etc/modprobe.d/ directory ending in .conf Example: vim /etc/modprobe.d/vfat.conf install vfat /bin/true Run the following command to unload the vfat module: # rmmod vfat

CCSS Severity:CCSS Metrics:
CCSS Score : 7.8Attack Vector: LOCAL
Exploit Score: 1.8Attack Complexity: LOW
Impact Score: 5.9Privileges Required: LOW
Severity: HIGHUser Interaction: NONE
Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HScope: UNCHANGED
 Confidentiality: HIGH
 Integrity: HIGH
 Availability: HIGH
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:72837
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:72020
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:68648
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:72734
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:84260
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:72943
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:72386
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:73048


OVAL    8
oval:org.secpod.oval:def:84260
oval:org.secpod.oval:def:72837
oval:org.secpod.oval:def:72734
oval:org.secpod.oval:def:72943
...
XCCDF    8
xccdf_org.secpod_benchmark_general_Amazon_Linux_AMI
xccdf_org.secpod_benchmark_general_CENTOS_7
xccdf_org.secpod_benchmark_general_RHEL_8
xccdf_org.secpod_benchmark_general_OEL_8
...

© SecPod Technologies