[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-92137-9

Platform: Amazon LinuxDate: (C)2018-10-29   (M)2022-10-10



Disable Apache Qpid (qpidd) The 'qpidd' service provides high speed, secure, guaranteed delivery services. It is an implementation of the Advanced Message Queuing Protocol. By default the qpidd service will bind to port 5672 and listen for connection attempts. The 'qpidd' service can be disabled with the following command: '$ sudo systemctl disable qpidd'


Parameter:


Technical Mechanism:

The qpidd service is automatically installed when the "base" package selection is selected during installation. The qpidd service listens for network connections, which increases the attack surface of the system. If the system is not intended to receive AMQP traffic, then the 'qpidd' service is not needed and should be disabled or removed. Fix: # # Disable qpidd.service for all systemd targets # systemctl disable qpidd.service # # Stop qpidd.service if currently running # systemctl stop qpidd.service

CCSS Severity:CCSS Metrics:
CCSS Score : Attack Vector:
Exploit Score: Attack Complexity:
Impact Score: Privileges Required:
Severity: User Interaction:
Vector: Scope:
 Confidentiality:
 Integrity:
 Availability:
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:48324
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:48790
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:48324


OVAL    2
oval:org.secpod.oval:def:48324
oval:org.secpod.oval:def:48790

© SecPod Technologies