[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-50385-4

Platform: cpe:/o:apple:mac_os_14Date: (C)2024-04-23   (M)2024-04-23



Automatic logon must be disabled. When automatic logons are enabled, the default user account is automatically logged on at boot time without prompting the user for a password. Even if the screen is later locked, a malicious user would be able to reboot the computer and find it already logged in. Disabling automatic logons mitigates this risk. Audit: Verify the macOS system is configured to disable unattended or automatic logon to the system with the following command: /usr/bin/osascript -l JavaScript << EOS $.NSUserDefaults.alloc.initWithSuiteName('com.apple.loginwindow')\ .objectForKey('com.apple.login.mcx.DisableAutoLoginClient').js EOS If the result is not "true", this is a finding. Remediation: Configure the macOS system to disable unattended or automatic logon to the system by installing the "com.apple.loginwindow" configuration profile with 'com.apple.login.mcx.DisableAutoLoginClient' key set to true


Parameter:

[Yes/No]


Technical Mechanism:

Configure the macOS system to disable unattended or automatic logon to the system by installing the "com.apple.loginwindow" configuration profile with 'com.apple.login.mcx.DisableAutoLoginClient' key set to true

CCSS Severity:CCSS Metrics:
CCSS Score : 7.6Attack Vector: PHYSICAL
Exploit Score: 0.9Attack Complexity: LOW
Impact Score: 6.0Privileges Required: NONE
Severity: HIGHUser Interaction: NONE
Vector: AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HScope: CHANGED
 Confidentiality: HIGH
 Integrity: HIGH
 Availability: HIGH
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:99383


OVAL    1
oval:org.secpod.oval:def:99383
XCCDF    1
xccdf_org.secpod_benchmark_general_Mac_OS_14

© SecPod Technologies